Deployment Architecture

Why aren't the logs coming in from a Linux server

test_qweqwe
Builder

I have 4 Linux servers in Forwarder Management (all of them callback) and I am collecting logs from auditd.
All of the 4 linux boxes have the same configuration and send logs to the heavy forwarder, but one of them stopped working.

What I checked:
1. Service Auditd.
2. Firewall.
3. Internet.
And all were good. What did I miss?

0 Karma
1 Solution

test_qweqwe
Builder

The problem was that one linux was in another subnet without access to the heavy forwarder.

View solution in original post

0 Karma

test_qweqwe
Builder

The problem was that one linux was in another subnet without access to the heavy forwarder.

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @test_qweqwe, Can you post your solution as an answer? You can then accept the solution to close the question. You'll receive some karma points this time as well. 🙂

test_qweqwe
Builder

Hello, @lfedak!
I did as you said.

P.S. Nice to see you again in my questions 😄

Get Updates on the Splunk Community!

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...