Getting Data In

Heavy Forwarder Kept sending logs after splunk was uninstalled from host.

tbyrne15
New Member

The only explanation I could think was that it was not uninstalled properly or it was over riding data somehow or it is was backlog?

If anyone has any idea what it might could be helpful thank you!

0 Karma

solarboyz1
Builder

Do you see any Splunk process running ? Do you see any splunk process holding any files/IO open?
Have you rebooted the system since the uninstall? Do you still see connection from the old heavy forwarder to the indexers?

Are there other heavy forwarders the data could be coming from?

If the inputs.conf has the wrong hostname, the events will appear to be from a different host. This can happen when images are cloned.

The same is true for the GUID, if you are seeing license usage ensure there isn't another host using the same GUID.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...