<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Heavy Forwarder Problem in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628169#M12299</link>
    <description>&lt;P&gt;You seem to have multiple separate problems here. So isolate them and try to troubleshoot one by one.&lt;/P&gt;&lt;P&gt;First question is what architecture do you have. Second - what _is_ working. Third - what change did you introduce lately. What was the expected behaviour after this change and what is the actual observed behaviour.&lt;/P&gt;&lt;P&gt;Don't try to do multiple things at once and then try to pinpoint why something is not working as expected because this way you can't track cause-effect relationships.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 16:25:12 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-01-24T16:25:12Z</dc:date>
    <item>
      <title>Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628141#M12297</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;I would like to inquire about some issues I am facing while setting up a heavy forwarder in splunk. Please take a look at the below issues :-&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Hosts are visible in splunk but all of them are not forwarding their logs to the indexer.&lt;/P&gt;&lt;P&gt;2) Linux server are not able to forward logs to the indexer.&lt;/P&gt;&lt;P&gt;3) Some host are able to forward their logs to indexer post a modification in their universal forwarder file manually, but it takes an hour or so before they forward their logs.&lt;/P&gt;&lt;P&gt;4) The most recently added do not show their logs in real time i.e. when a time frame recently added devices should logs in last 4 hours or 60 minutes but they do show only post 24 hours time filter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 13:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628141#M12297</guid>
      <dc:creator>Darsh1561</dc:creator>
      <dc:date>2023-01-24T13:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628167#M12298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253185"&gt;@Darsh1561&lt;/a&gt;m,&lt;/P&gt;&lt;P&gt;please detail your questions:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) Hosts are visible in splunk but all of them are not forwarding their logs to the indexer.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;you mean that you see some hosts in the Deployment Server but that you don't see their logs or what else?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) Linux server are not able to forward logs to the indexer.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;are you meaning that all your Linux servers don't sed logs?&lt;/P&gt;&lt;P&gt;I suppose that you already configured:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;your indexers and your Heavy Forwarders to receive logs,&lt;/LI&gt;&lt;LI&gt;your Forwarders to send logs to the Indexers or to Heavy Forwarders,&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;how did you do this?&lt;/P&gt;&lt;P&gt;did you checked that the firewall routes between Forwarders and Indexers and Heavy Forwarders are open?&lt;/P&gt;&lt;P&gt;What's you architecture?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3) Some host are able to forward their logs to indexer post a modification in their universal forwarder file manually, but it takes an hour or so before they forward their logs.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Which local configuration did you do?&lt;/P&gt;&lt;P&gt;are you using a Deployment server?&lt;/P&gt;&lt;P&gt;have you followed the instructions at&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/resources/videos/getting-data-in-with-forwarders.html" target="_blank"&gt;https://www.splunk.com/en_us/resources/videos/getting-data-in-with-forwarders.html&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Forwarding/Aboutforwardingandreceivingdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Forwarding/Aboutforwardingandreceivingdata&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4) The most recently added do not show their logs in real time i.e. when a time frame recently added devices should logs in last 4 hours or 60 minutes but they do show only post 24 hours time filter.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;did you checked the timestamp of these events, is it correct?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 16:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628167#M12298</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-24T16:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628169#M12299</link>
      <description>&lt;P&gt;You seem to have multiple separate problems here. So isolate them and try to troubleshoot one by one.&lt;/P&gt;&lt;P&gt;First question is what architecture do you have. Second - what _is_ working. Third - what change did you introduce lately. What was the expected behaviour after this change and what is the actual observed behaviour.&lt;/P&gt;&lt;P&gt;Don't try to do multiple things at once and then try to pinpoint why something is not working as expected because this way you can't track cause-effect relationships.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 16:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628169#M12299</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-24T16:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628709#M12303</link>
      <description>&lt;P&gt;Thanks for your input.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 15:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/628709#M12303</guid>
      <dc:creator>Darsh1561</dc:creator>
      <dc:date>2023-01-28T15:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/629826#M12365</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp; that make sense&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 05:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/629826#M12365</guid>
      <dc:creator>aad</dc:creator>
      <dc:date>2023-02-07T05:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/629839#M12366</link>
      <description>&lt;P&gt;Hi at all,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 07:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Heavy-Forwarder-Problem/m-p/629839#M12366</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-07T07:30:15Z</dc:date>
    </item>
  </channel>
</rss>

