<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange UF behaviour - NO _internal forwarded!!! in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560015#M92589</link>
    <description>&lt;P&gt;Done! First action... &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Network is ok, Indexers are ok, i'm receiving datas from other UFs, no problem...&lt;/P&gt;&lt;P&gt;All inputs logs in the issued-UF are less then 50MB...&lt;/P&gt;&lt;P&gt;Also limits thruput is set to 0... no way!!! 48h UF got down, and now has issues... queues are empty!!! &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tried all workarounds... the only way is deleting inputs that generates the issue...&lt;/P&gt;&lt;P&gt;Maybe server is locked, maybe some log is locked, and loops sending data...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll get an eye on this host, and see next days...&lt;BR /&gt;Thanks &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 10:23:09 GMT</pubDate>
    <dc:creator>verbal_666</dc:creator>
    <dc:date>2021-07-19T10:23:09Z</dc:date>
    <item>
      <title>Strange UF behaviour - NO _internal forwarded!!!</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/559993#M92586</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I have a strange behaviour from about 48h by an UF, a single one.&lt;/P&gt;&lt;P&gt;1) On UF both metrics and splunkd logs events, NO ERRORS! Connections to outputs is OK!&lt;BR /&gt;2) UF has not been touched in last 48h, same conf / same addons / same ALL&lt;BR /&gt;3) UF has been updated to clean 7.2.0, but problem permains &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt; rolled back to previous version...&lt;BR /&gt;4) All inputs are sent, _internal (metrics.log/splunkd.log) NOT from 48h!!!&lt;BR /&gt;5) I still clean log dir on UF from rotated *.? and online metrics and splunkd, and restarted!!! No way!!!&lt;BR /&gt;6) Deleted addons, and redeployed. No way!!!&lt;/P&gt;&lt;P&gt;_internal are missing!!!&lt;/P&gt;&lt;P&gt;Any idea?&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 07:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/559993#M92586</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2021-07-19T07:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strange UF behaviour - NO _internal forwarded!!!</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560007#M92587</link>
      <description>&lt;P&gt;Got the problem. And it's even stranger.&lt;/P&gt;&lt;P&gt;An addon, with many many file monitor inputs, is blocking these inputs and also _internal... &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Others inputs in other addons work.&lt;/P&gt;&lt;P&gt;Strange, very strange!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 09:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560007#M92587</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2021-07-19T09:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Strange UF behaviour - NO _internal forwarded!!!</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560009#M92588</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28550"&gt;@verbal_666&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I found this behavior when the forwarder and/or the network and/or the Indexers are overloaded, so Splunk internal logs are skipped because they have a lower priority.&lt;/P&gt;&lt;P&gt;Check if you have (or had) one of the above problems.&lt;/P&gt;&lt;P&gt;Then check the volume of logs sent by that Forwarder and see if reducing those logs you continue to have the problem.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 09:39:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560009#M92588</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-19T09:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Strange UF behaviour - NO _internal forwarded!!!</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560015#M92589</link>
      <description>&lt;P&gt;Done! First action... &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Network is ok, Indexers are ok, i'm receiving datas from other UFs, no problem...&lt;/P&gt;&lt;P&gt;All inputs logs in the issued-UF are less then 50MB...&lt;/P&gt;&lt;P&gt;Also limits thruput is set to 0... no way!!! 48h UF got down, and now has issues... queues are empty!!! &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tried all workarounds... the only way is deleting inputs that generates the issue...&lt;/P&gt;&lt;P&gt;Maybe server is locked, maybe some log is locked, and loops sending data...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll get an eye on this host, and see next days...&lt;BR /&gt;Thanks &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 10:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560015#M92589</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2021-07-19T10:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Strange UF behaviour - NO _internal forwarded!!!</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560020#M92590</link>
      <description>&lt;P&gt;Gotcha!!!&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;Maybe server is locked, maybe some log is locked, and loops sending data...&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;For some reason, server has some fs locked, also an ls locks the terminal sessions!!! &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So SPL UF locks on those paths... blocking all the rest of inputs.conf!!!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 19:59:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Strange-UF-behaviour-NO-internal-forwarded/m-p/560020#M92590</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2021-07-19T19:59:10Z</dc:date>
    </item>
  </channel>
</rss>

