Getting Data In

Heavy Forwarder Kept sending logs after splunk was uninstalled from host.

tbyrne15
New Member

The only explanation I could think was that it was not uninstalled properly or it was over riding data somehow or it is was backlog?

If anyone has any idea what it might could be helpful thank you!

0 Karma

solarboyz1
Builder

Do you see any Splunk process running ? Do you see any splunk process holding any files/IO open?
Have you rebooted the system since the uninstall? Do you still see connection from the old heavy forwarder to the indexers?

Are there other heavy forwarders the data could be coming from?

If the inputs.conf has the wrong hostname, the events will appear to be from a different host. This can happen when images are cloned.

The same is true for the GUID, if you are seeing license usage ensure there isn't another host using the same GUID.

0 Karma
Get Updates on the Splunk Community!

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...