Hello,
I was wondering if Splunk had any 7.x Universal Forwarders that had known problems or bugs such as not sending logs even though service is running, or other similiar issues that could cause the process and or service to crash?
Regards,
If you have instances of Splunk UFs crashing then you should open a support case with Splunk.
Not necessarily crashing but I was wondering if there have been any cases where it has
Hi
I haven't heard this kind of bug for UF. In this kind of situations there is usually some configuration issues on UF or indexer side.
Can you give more information about your environment and also inputs.conf, outputs.conf etc. so we can try to help you?
r. Ismo
Hello,
I will try to gather all the confs under the [SPLUNK HOME]/etc/system/local/ directory to see what the issue could be from.
Thank you for your response