Getting Data In

Heavy Forwarder Slow to Start Forwarding Syslog

DBattisto
Communicator

Hello-

My current setup:
Device Syslog --> Syslog Server w/ Splunk HvyFwd --> Splunk Indexer

When I restart my Heavy Forwarder server or Splunkd, it takes up to 30 minutes to begin forwarding syslogs to the indexer. Is this due to the number of devices and folders stored within the syslog server, and is there a way to speed this process up?

Thanks,

0 Karma

broberg
Communicator

When you stop splunk it still keep getting the syslog meaning when you start again it is falling behind and can't catch up in time (for some reason)
I would look on the queues on on the HF and on the indexing tier to see where the bottleneck is.
I would also look in the internal log and see if there is any errors on the monitoring path (to big files or such error)

0 Karma

manjunathmeti
Champion

Check number of directories and files monitored by the forwarder.
$SPLUNK_HOME/bin/splunk list monitor

0 Karma

mydog8it
Builder

Can you share details of how you are determining the delay is on the HF? Why are you using an HF on the syslog server?

0 Karma

DBattisto
Communicator

Thanks for the response!

I run heavy forwarder on top of my syslog server and it is actively monitoring the device directories. This was recommended to me as best practice a few years back. It works wonderfully, it just takes a while to start again after restarting the heavy forwarder.

I've monitored the syslog file of a device using tail -f and see that it's being updated instantly. If I look in splunkd.log after a restart, it takes 15-20 minutes to go through and say that it's going to begin monitoring all of the directories specified. My file hierarchy is as follows:

DeviceType/DeviceName/date.log
example: CiscoSwitch/Switch69/20200212.log

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...