Alerting

Splunk UI not showing data for one host

rdonnelly001
New Member

Hi,

I am running splunk enterprise in which we have multiple hosts sending data using the universal forwarder.

I have one host which was displaying data fine on the UI however stopped randomly at 22:40.

Checking the physical server it is connected to the splunk host and forwarding data ( i can see it processing the files using the webpage admin)

The host is also receiving the data from the server (can see the info messages for metrics from the host) however when i search the host on the UI i see all data up till 22:40 and nothing after.

No configuration changes were made or anything.

This is only affecting 1 host out of many.

Tags (1)
0 Karma

jgbricker
Contributor

If restarting the splunk service on the client doesnt fix it. I recommend reinstalling the forwarder and sending the configuration back down via your deployer or manually depending in you setup. Honestly in my experience it it not worth the time isolating/troubleshooting a client.

0 Karma

rdonnelly001
New Member

i tried an upgrade which didn't work.

I guess next step is to wipe the install completely and then re-deploy the forwarder as said.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...