Getting Data In

Distributed Deployment Environment all UNIX forwarders missing

mookiie2005
Communicator

We are trying to replace our current indexer with two new indexers. We made updates in outputs.conf to reflect the new servers. We ran a deployment to initiate the change and after the deployment all of our windows forwarders were fine and showed up, but we are no longer receiving data from any of our unix forwarders and we are not sure why? - We re-deployed our original configuration for the time being until we can work out our issue.

0 Karma

mookiie2005
Communicator

I reviewed the splunk logs and the unix configuration and it looks like that the splunk forwarders were never restarted after the deployment of the configuration files. Anyone know how I can check what the reason is that the splunk forwarders were never resstarted? Would that vbe on the deploymnet server logs or on teh forwarders themselves?

0 Karma

samjack
New Member

I would run this on one of the servers having the issue after you try and make the change on that host. And restart splunk. See if it still shows old value. If so you likely have another outputs.conf taking precedence somewhere.

/splunk btool outputs list

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...