Getting Data In

Distributed Deployment Environment all UNIX forwarders missing

mookiie2005
Communicator

We are trying to replace our current indexer with two new indexers. We made updates in outputs.conf to reflect the new servers. We ran a deployment to initiate the change and after the deployment all of our windows forwarders were fine and showed up, but we are no longer receiving data from any of our unix forwarders and we are not sure why? - We re-deployed our original configuration for the time being until we can work out our issue.

0 Karma

mookiie2005
Communicator

I reviewed the splunk logs and the unix configuration and it looks like that the splunk forwarders were never restarted after the deployment of the configuration files. Anyone know how I can check what the reason is that the splunk forwarders were never resstarted? Would that vbe on the deploymnet server logs or on teh forwarders themselves?

0 Karma

samjack
New Member

I would run this on one of the servers having the issue after you try and make the change on that host. And restart splunk. See if it still shows old value. If so you likely have another outputs.conf taking precedence somewhere.

/splunk btool outputs list

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...