Deployment Architecture

Splunkforwarder stopped sending data randomly

qfulgham
New Member

Hey Guys!

So I have 2 forwarders they had stopped sending current data, I looked over the splunk config with a splunk contractor and found their was nothing wrong with the splunk config. So he told me to check and see if there were possibly any firewalls rules blocking traffic, so I went to the FW team and everything seems good from that aspect because out of nowhere one of the servers starts reporting data again, but the other server is still no reporting data......would anybody have any idea what could be wrong?

  • I checked to make sure the splunkwarder was running with the ./splunk status
  • I made sure the files were being monitored on the forwarder with the ./splunk list monitor command
  • I made sure the timestamp was okay by checking the time on the event versus its _time (but the servers are located in eastern time so time format shouldn't be an issue) (And plus the other server started pulling current data, and they have the same splunk config)

Would there be any other thing I should check that I haven't listed above?

Thanks for the help!

Tags (2)
0 Karma

adonio
Ultra Champion

hello there,
first check if you can see data from forwarders in index=_internal
if so, it means the forwarders do send data to indexers and therefore check inputs
another option is to follow that article:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata
hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...