<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing events syslog forwarding to heavy forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-syslog-forwarding-to-heavy-forwarder/m-p/554745#M91913</link>
    <description>&lt;P&gt;I need help troubleshooting an issue where I am missing events being forwarded from a linux syslog daemon to my heavy forwarders. Beginning the first day of each month, for three or four days, this feed drops from ~50,000 indexed events per hour to maybe ~150. Then, magically, the feed resumes ~50,000 events per hour for the remainder of the month. Only this one index source is affected. All traffic is UDP.&lt;/P&gt;&lt;P&gt;To troubleshoot:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I've removed the load balancer from the equation and send directly to one heavy forwarder&lt;/LI&gt;&lt;LI&gt;We can see the syslog events leaving the source server&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Using tcpdump, I can see events from the source server hitting port 514 on the heavy forwarder&lt;/LI&gt;&lt;LI&gt;I have a dashboard showing blocking on agg, index, parsing and typing queues. There is none.&lt;/LI&gt;&lt;LI&gt;I tested the regexs in my transforms on the actual events captured with tcpdump. All test correctly.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;While this event was in progress&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Opened a support case with diag logs from the HWF and one of my indexer servers (nothing yet)&lt;/LI&gt;&lt;LI&gt;There are no errors or warnings in the internal logs for the heavy forwarder used in this test.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I've looked at all the log channels on the HWF (1236 of them) but I don't know which one(s) to elevate the logging level for&lt;/LI&gt;&lt;LI&gt;I tried starting splunk with --debug but I do not see any additional internal logging. I may not have done this correctly. (splunk start --debug)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;More strange&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;There are two syslog feeds from the source server being used in this troubleshooting effort. The second feed is unaffected.&lt;/LI&gt;&lt;LI&gt;There are 78 source servers in this group. All exhibit the same behavior making it seem that splunk is the common denominator.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I do use a props and transforms configuration for port 514 to parse the index name and sourcetype for a multitude of incoming syslog feeds bound for different indexes. This configuration has not changed for a very long time (and does not change at the first of the month - for a few days).&lt;/P&gt;&lt;P&gt;Frankly I'm lost. There must be a way to expose what is happening to these events either at the heavy forwarder or on the indexers but I'm out of ideas. Does anyone have a thought about how I might capture the information I need to diagnose whatever is happening? At this time, the feed has returned to normal i.e. ~50,000 indexed events per hour. Thank you in advance for any advice you have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jun 2021 17:28:28 GMT</pubDate>
    <dc:creator>w199284</dc:creator>
    <dc:date>2021-06-07T17:28:28Z</dc:date>
    <item>
      <title>Missing events syslog forwarding to heavy forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-syslog-forwarding-to-heavy-forwarder/m-p/554745#M91913</link>
      <description>&lt;P&gt;I need help troubleshooting an issue where I am missing events being forwarded from a linux syslog daemon to my heavy forwarders. Beginning the first day of each month, for three or four days, this feed drops from ~50,000 indexed events per hour to maybe ~150. Then, magically, the feed resumes ~50,000 events per hour for the remainder of the month. Only this one index source is affected. All traffic is UDP.&lt;/P&gt;&lt;P&gt;To troubleshoot:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I've removed the load balancer from the equation and send directly to one heavy forwarder&lt;/LI&gt;&lt;LI&gt;We can see the syslog events leaving the source server&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Using tcpdump, I can see events from the source server hitting port 514 on the heavy forwarder&lt;/LI&gt;&lt;LI&gt;I have a dashboard showing blocking on agg, index, parsing and typing queues. There is none.&lt;/LI&gt;&lt;LI&gt;I tested the regexs in my transforms on the actual events captured with tcpdump. All test correctly.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;While this event was in progress&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Opened a support case with diag logs from the HWF and one of my indexer servers (nothing yet)&lt;/LI&gt;&lt;LI&gt;There are no errors or warnings in the internal logs for the heavy forwarder used in this test.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I've looked at all the log channels on the HWF (1236 of them) but I don't know which one(s) to elevate the logging level for&lt;/LI&gt;&lt;LI&gt;I tried starting splunk with --debug but I do not see any additional internal logging. I may not have done this correctly. (splunk start --debug)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;More strange&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;There are two syslog feeds from the source server being used in this troubleshooting effort. The second feed is unaffected.&lt;/LI&gt;&lt;LI&gt;There are 78 source servers in this group. All exhibit the same behavior making it seem that splunk is the common denominator.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I do use a props and transforms configuration for port 514 to parse the index name and sourcetype for a multitude of incoming syslog feeds bound for different indexes. This configuration has not changed for a very long time (and does not change at the first of the month - for a few days).&lt;/P&gt;&lt;P&gt;Frankly I'm lost. There must be a way to expose what is happening to these events either at the heavy forwarder or on the indexers but I'm out of ideas. Does anyone have a thought about how I might capture the information I need to diagnose whatever is happening? At this time, the feed has returned to normal i.e. ~50,000 indexed events per hour. Thank you in advance for any advice you have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 17:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-syslog-forwarding-to-heavy-forwarder/m-p/554745#M91913</guid>
      <dc:creator>w199284</dc:creator>
      <dc:date>2021-06-07T17:28:28Z</dc:date>
    </item>
  </channel>
</rss>

