Getting Data In

Forwarder Stops sending Data and starts sending once restart is done?

raghu0463
Explorer

Hi, 

multiple Forwarders stops sending data for no reason for every 20 days , but when a restart is done, all starts sending normally. there are no warning or error logs in splunkd either. not sure what's causing the issue.
This issue is happening on same forwarders every time. 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @raghu0463,

maybe the stop sending is from the 1st until the 12nd of the month?

if this is true, please check the timestamp format that probably is in european format (dd/mm/yyyy) and Splunk reads in american format (mm/dd/yyyy).

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you give some more information to us to help you? Like inputs, splunk and os version, have it works earlier etc.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...