<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why my intermediate forwarder is not working, causing 600 universal forwarders to not send data to indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125351#M97710</link>
    <description>&lt;P&gt;follow @martin_mueller advice and check the servers ulimit settings; usually if something works for a few minutes and then stops on *nix systems, indicates ulimit being too low.  &lt;/P&gt;</description>
    <pubDate>Sat, 15 Nov 2014 10:07:42 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-11-15T10:07:42Z</dc:date>
    <item>
      <title>How to troubleshoot why my intermediate forwarder is not working, causing 600 universal forwarders to not send data to indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125349#M97708</link>
      <description>&lt;P&gt;I have a ticket in with support but this may be faster.&lt;/P&gt;

&lt;P&gt;My intermediate forwarder is not working right.  When I restart it, everything works for a few minutes then stops working.  I have checked everything that I know to help.&lt;/P&gt;

&lt;P&gt;Please help with suggestions. 600 systems are down!!!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2014 00:58:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125349#M97708</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-11-15T00:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my intermediate forwarder is not working, causing 600 universal forwarders to not send data to indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125350#M97709</link>
      <description>&lt;P&gt;Usually there would be some indication of what's wrong in the IF's internal logs, especially splunkd.log.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2014 09:55:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125350#M97709</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-11-15T09:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my intermediate forwarder is not working, causing 600 universal forwarders to not send data to indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125351#M97710</link>
      <description>&lt;P&gt;follow @martin_mueller advice and check the servers ulimit settings; usually if something works for a few minutes and then stops on *nix systems, indicates ulimit being too low.  &lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2014 10:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125351#M97710</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-15T10:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my intermediate forwarder is not working, causing 600 universal forwarders to not send data to indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125352#M97711</link>
      <description>&lt;P&gt;Splunk Support was relatively quick to respond.  Rajpal Bal got on the line and at my request she quickly setup a webex.  we looked at SOS and could see that the tcpout on the Intermediate forwarder (IF) was full and the tcpin for the indexers was very low.  on Thursday there was a mix up in DNS but this did not affect the IF until Splunk was restarted yesterday. Rajpal suggested and helped me to add the connection_host entry below to the inputs.conf to force Splunk to use IP and not look-up DNS names.  we did this on both the IF and the indexers.  it did not immediately resolve the issues but over a few hours the IF started its normal behavior and we can fix DNS on Monday.&lt;/P&gt;

&lt;P&gt;Thanks Rajpal, for fast, appropriate and extra effort in staying beyond work hours to solve this tricky problem&lt;/P&gt;

&lt;P&gt;in the inputs.conf that has the "splunktcp" stanza the "connection_host = ip" for app ports like below &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[splunktcp:://]&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;connection_host = ip&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2014 12:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-intermediate-forwarder-is-not-working/m-p/125352#M97711</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-11-15T12:59:58Z</dc:date>
    </item>
  </channel>
</rss>

