Getting Data In

Forwarder stopped forwarding after restart of server

johnsmithman2
New Member

I am using the VMware Syslog collector to collect the logs from my ESXi hosts and send them to Splunk with the universal forwarder. Everything was working great until I restarted the server with the Syslog collector and the universal forwarder today. The logs are no longer being forwarded or Splunk is not indexing the received messages, what could cause this?

I know it is not a problem with the VMware Syslog collector because the service is running fine and the logs are being updated from the ESXi hosts.

Any ideas on what causes this after a restart?

Tags (1)
0 Karma

idsiano
Explorer

In this thread it was explained that is a VMWare issue

0 Karma

kreszan
Explorer

I have similar issue @ 6.0. Any resolution to this ?

0 Karma

mrflibbleuk
New Member

Did you get any resolution to this one? I have had a similar issue, when I restarted the main Splunk server the Heavy forwarders seem to be unable to communicate to the server. Looking at the forwarder event logs I am getting an 'eventType=connect_fail' everytime it attempts to connect.

Sometimes restarting the splunk forwarder makes it psring back into life.

0 Karma

johnsmithman2
New Member

Yes it is, I should have mentioned that also.

0 Karma

Drainy
Champion

Have you verified that the universal forwarder is also still running?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...