<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Receiving Events in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79715#M12235</link>
    <description>&lt;P&gt;We have enterprise license with license level of 500MB.&lt;BR /&gt;
version 4.0.4, build 67724 &lt;BR /&gt;
I have around 100 host has been setup for forwarding. &lt;/P&gt;

&lt;P&gt;Everything looks good but when running # netstat it is showing "FIN_WAIT_2" &amp;amp; "CLOSE_WAIT".&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;etherealtrace&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;tshark -i bnx0 port 9997&lt;BR /&gt;
Capturing on bnx0&lt;BR /&gt;
  0.000000 192.10.21.12 -&amp;gt; 192.10.21.121 TCP 40711 &amp;gt; palace-6 [ACK] Seq=1 Ack=1 Win=1460 Len=0 TSV=3020080923 TSER=789430684&lt;BR /&gt;
  0.000034 192.10.21.12 -&amp;gt; 192.10.21.121 TCP [TCP ZeroWindow] [TCP ACKed lost segment] palace-6 &amp;gt; 40711 [ACK] Seq=1 Ack=2 Win=0 Len=0 TSV=789442682 TSER=3019755295&lt;BR /&gt;
  0.267301 192.10.21.12 -&amp;gt; 192.10.21.121 TCP 34658 &amp;gt; palace-6 [ACK] Seq=1 Ack=1 Win=46 Len=0 TSV=2742660555 TSER=789430709&lt;BR /&gt;
  0.267310 192.10.21.12 -&amp;gt; 192.10.21.121 TCP [TCP ZeroWindow] [TCP ACKed lost segment] palace-6 &amp;gt; 34658 [ACK] Seq=1 Ack=2 Win=0 Len=0 TSV=789442709 TSER=2742548382&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:27:10 GMT</pubDate>
    <dc:creator>royalchandu</dc:creator>
    <dc:date>2020-09-28T11:27:10Z</dc:date>
    <item>
      <title>Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79713#M12233</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;

&lt;P&gt;This is Chandan and my splunk server was working fine but after few hours it stucked and now from last 2 days i am not getting any events on it.&lt;/P&gt;

&lt;P&gt;I restarted the spunk daemon couple of times but no luck.&lt;/P&gt;

&lt;P&gt;Please assist &amp;amp; advise.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Chandan&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 20:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79713#M12233</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-02-27T20:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79714#M12234</link>
      <description>&lt;P&gt;Could you provide us more information? like what version of splunk you are running and on what platform, how many forwarder sending data to splunk?, what type of forwarder is it?, are you using free version or the enterprise version?&lt;/P&gt;

&lt;P&gt;First thing you can check if your splunk server logs are getting indexed in splunk. If its indexing then check the network connectivity from forwarder to the servers(if you have firewalls in between). If connectivity is fine, check on the forwarder configuration and logs for any errors. &lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 20:33:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79714#M12234</guid>
      <dc:creator>npandith</dc:creator>
      <dc:date>2012-02-27T20:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79715#M12235</link>
      <description>&lt;P&gt;We have enterprise license with license level of 500MB.&lt;BR /&gt;
version 4.0.4, build 67724 &lt;BR /&gt;
I have around 100 host has been setup for forwarding. &lt;/P&gt;

&lt;P&gt;Everything looks good but when running # netstat it is showing "FIN_WAIT_2" &amp;amp; "CLOSE_WAIT".&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;etherealtrace&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;tshark -i bnx0 port 9997&lt;BR /&gt;
Capturing on bnx0&lt;BR /&gt;
  0.000000 192.10.21.12 -&amp;gt; 192.10.21.121 TCP 40711 &amp;gt; palace-6 [ACK] Seq=1 Ack=1 Win=1460 Len=0 TSV=3020080923 TSER=789430684&lt;BR /&gt;
  0.000034 192.10.21.12 -&amp;gt; 192.10.21.121 TCP [TCP ZeroWindow] [TCP ACKed lost segment] palace-6 &amp;gt; 40711 [ACK] Seq=1 Ack=2 Win=0 Len=0 TSV=789442682 TSER=3019755295&lt;BR /&gt;
  0.267301 192.10.21.12 -&amp;gt; 192.10.21.121 TCP 34658 &amp;gt; palace-6 [ACK] Seq=1 Ack=1 Win=46 Len=0 TSV=2742660555 TSER=789430709&lt;BR /&gt;
  0.267310 192.10.21.12 -&amp;gt; 192.10.21.121 TCP [TCP ZeroWindow] [TCP ACKed lost segment] palace-6 &amp;gt; 34658 [ACK] Seq=1 Ack=2 Win=0 Len=0 TSV=789442709 TSER=2742548382&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79715#M12235</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2020-09-28T11:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79716#M12236</link>
      <description>&lt;P&gt;Also we have a license violation issues going on this Splunk server.&lt;BR /&gt;
 1. I have stop couple of splunk forwarder clients on my network.&lt;BR /&gt;
 2. It happened few weeks back too but that time we just restart the splunk it started again. But after that again it went down.&lt;/P&gt;

&lt;P&gt;Please assist me which log i should check to see if i am getting events.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 21:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79716#M12236</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-02-27T21:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79717#M12237</link>
      <description>&lt;P&gt;If you are running an enterprise trial license, you only get 3 violations. If you are running the full enterprise, you are allowed 5 violations in a 30-day period.&lt;/P&gt;

&lt;P&gt;Run this search to see your violation status:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_audit.log | 
eval MB_indexed_today = round(todaysBytesIndexed / (1024 * 1024),1) | 
table _time log_level quotaExceededCount lastExceededDate, MB_indexed_today
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Run this search to see the status of your forwarders:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" group=tcpin_connections | 
eval sourceHost=if(isnull(hostname), sourceHost,hostname) | 
eval connectionType=case(fwdType=="uf","Universal Forwarder", fwdType=="lwf", "Light Weight Forwarder",fwdType=="full", "Splunk Indexed", connectionType=="cooked" or connectionType=="cookedSSL","Splunk Forwarder", connectionType=="raw" or connectionType=="rawSSL","Legacy Forwarder") | 
eval build=if(isnull(build),"n/a",build) | 
eval version=if(isnull(version),"pre 4.2",version) | 
eval guid=if(isnull(guid),sourceHost,guid) | 
eval os=if(isnull(os),"n/a",os)| eval arch=if(isnull(arch),"n/a",arch) | 
eval my_splunk_server = splunk_server | 
fields connectionType sourceIp sourceHost sourcePort destPort kb tcp_eps tcp_Kprocessed tcp_KBps my_splunk_server build version os arch | 
eval lastReceived = if(kb&amp;gt;0, _time, null) | 
stats first(sourceIp) as sourceIp first(connectionType) as connectionType first(sourcePort) as sourcePort first(build) as build first(version) as version first(os) as os first(arch) as arch max(_time) as lastConnected max(lastReceived) as lastReceived sum(kb) as kb avg(tcp_eps) as avg_eps by sourceHost | 
stats first(sourceIp) as sourceIp first(connectionType) as connectionType first(sourcePort) as sourcePort first(build) as build first(version) as version first(os) as os first(arch) as arch max(lastConnected) as lastConnected max(lastReceived) as lastReceived first(kb) as KB first(avg_eps) as eps by sourceHost | 
eval status = if(isnull(KB) or lastConnected&amp;lt;(info_max_time-900),"missing",if(lastConnected&amp;gt;(lastReceived+300) or KB==0,"quiet","active")) |
 sort sourceHost
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(And yes, I took the second search from the Splunk Deployment Monitor...)&lt;BR /&gt;
Maybe this will help you see the problem. Run the searches over at least the last 7 days. Last 30 days might be even better.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 22:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79717#M12237</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-02-27T22:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79718#M12238</link>
      <description>&lt;P&gt;thanks for your response well i tried this and i do have license violation issues but its was few months back ... could you please advise me if this is due to license violation than how much time it will take to start getting events back...&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 18:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79718#M12238</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-03-06T18:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79719#M12239</link>
      <description>&lt;P&gt;thanks for your response well i tried this and i do have license violation issues but its was few months back ... could you please advise me if this is due to license violation than how much time it will take to start getting events back...&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 18:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79719#M12239</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-03-06T18:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Events</title>
      <link>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79720#M12240</link>
      <description>&lt;P&gt;Here is a link to the docs re: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.1/Admin/Aboutlicenseviolations"&gt;license violations&lt;/A&gt;. Splunk does not stop indexing data, but it doesn't allow you to search the data when you have exceeded 3 violations on a free license. I believe that this will reset after 30 days of no violations. But check the manual. If you are still having trouble, go to splunk.com and file a support ticket.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2012 22:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Not-Receiving-Events/m-p/79720#M12240</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-03-07T22:08:53Z</dc:date>
    </item>
  </channel>
</rss>

