Deployment Architecture

Forwarder stopped pushing performance data

siddharthmis
Explorer

Hi,

I had a completely working setup where forwarder was pushing data to UF successfully but it stopped pushing data a week earlier.
There is no error in splunkd.log which can explain the reason.

How do I fix it?

All other indexes are working fine. It's just that performance counters are not pushed. Registry values are fine.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi siddharthmis,
only three foolish questions:

  • forwarder time and date are the same of Indexers?
  • did you checked if you're receiving logs in _internal index?
  • surely you checked connection using telnet (telnet indexer_IP 9997).

Bye.
Giuseppe

0 Karma

adonio
Ultra Champion

Hi siddharthmis,
do you mean forwarder pushed data to another forwarder (UF) ? or forwarder sending data to indexer and now it does not send data anymore?

0 Karma

siddharthmis
Explorer

I mean it stopped pushing data to Splunk deployment (indexer)

0 Karma

tlam_splunk
Splunk Employee
Splunk Employee

Hi siddharthmis, are you using Window Perfmon stanza in the UF ?

0 Karma

ppeterson
Path Finder

version/OS info would help, have you tried restarting from the CLI?

0 Karma

siddharthmis
Explorer

Yes but in Vain

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...