Hi All,
Good day, would like to seek for help regarding on our universal forwarders. Some of our sources (universal forwarder) intermittently stops forwarding logs. I don't know why, firewall definition is intact, if you telnet splunk ports from the sources, the results are good. However, when checking splunkd.log
, Cooked Connection, Raw Connection, Ping connection and Connection TIme out can be seen. Please help. Thanks.
Universal Forwarder Versions are:
6.2.6, 6.4.0
Splunk Enterprise Infra and versions:
6 Indexers: 6.6.1
3 Heavy Forwarders: 6.6.1
2 SH: 6.6.1
Regards,
Dan
@dantimola will give you +30 Karma points for answering this question.
I've conducted health check on our infra. Maybe this can help. Looks like the event-processing queues is having an issue. How can I optimize/resolve this? Thanks.