Deployment Architecture

Splunkforwarder stopped sending data randomly

qfulgham
New Member

Hey Guys!

So I have 2 forwarders they had stopped sending current data, I looked over the splunk config with a splunk contractor and found their was nothing wrong with the splunk config. So he told me to check and see if there were possibly any firewalls rules blocking traffic, so I went to the FW team and everything seems good from that aspect because out of nowhere one of the servers starts reporting data again, but the other server is still no reporting data......would anybody have any idea what could be wrong?

  • I checked to make sure the splunkwarder was running with the ./splunk status
  • I made sure the files were being monitored on the forwarder with the ./splunk list monitor command
  • I made sure the timestamp was okay by checking the time on the event versus its _time (but the servers are located in eastern time so time format shouldn't be an issue) (And plus the other server started pulling current data, and they have the same splunk config)

Would there be any other thing I should check that I haven't listed above?

Thanks for the help!

Tags (2)
0 Karma

adonio
Ultra Champion

hello there,
first check if you can see data from forwarders in index=_internal
if so, it means the forwarders do send data to indexers and therefore check inputs
another option is to follow that article:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata
hope it helps

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...