Getting Data In

Heavy Forwarder not receiving logs

vnguyen46
Contributor

Hi,
After migrated Splunk Enterprise to a new hardware, my HFs stop receiving logs over port 514/1514. It's verified these ports are open on the new HFs. The new system is receiving logs from UFs running on Windows and from Cloud-based (AWS).

What other configuration needs to be done like syslog daemon or any things else for the new HFs to receive logs being sent over port 514/1514 like F5 and other network devices?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the ports have a listener on them. Check your firewall(s) to ensure connectivity.
If the HF moved to a new address, make sure all clients have that address.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Don't you think I need to configure the daemon syslog on the new HFs so they can receive the logs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you absolutely need to do that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Hi Richgalloway,

I'd like to circle back on HFs stopped receiving logs. All logs were once received well after system admin fixed the daemon log. Then last Thursday, HFs suddenly stopped receiving 9 out of 10 logs at almost same time. There is no issue with new logs. Disk space and network connection are not the cause.

Would you please share what you think?

Thank you,

0 Karma

vnguyen46
Contributor

"Verify the ports have a listener on them" - would you please give more details on this?

Thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use netstat -ln | grep 514.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

I used nc and received this:
ss -lnt4p | grep 514
LISTEN 0 128 :514 *:
LISTEN 0 128 127.0.0.1:51490 :
LISTEN 0 128 :1514 *:

Does that mean I have listeners on both 514 and 1514?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...