Getting Data In

Heavy Forwarder not receiving logs

vnguyen46
Contributor

Hi,
After migrated Splunk Enterprise to a new hardware, my HFs stop receiving logs over port 514/1514. It's verified these ports are open on the new HFs. The new system is receiving logs from UFs running on Windows and from Cloud-based (AWS).

What other configuration needs to be done like syslog daemon or any things else for the new HFs to receive logs being sent over port 514/1514 like F5 and other network devices?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the ports have a listener on them. Check your firewall(s) to ensure connectivity.
If the HF moved to a new address, make sure all clients have that address.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Don't you think I need to configure the daemon syslog on the new HFs so they can receive the logs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you absolutely need to do that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Hi Richgalloway,

I'd like to circle back on HFs stopped receiving logs. All logs were once received well after system admin fixed the daemon log. Then last Thursday, HFs suddenly stopped receiving 9 out of 10 logs at almost same time. There is no issue with new logs. Disk space and network connection are not the cause.

Would you please share what you think?

Thank you,

0 Karma

vnguyen46
Contributor

"Verify the ports have a listener on them" - would you please give more details on this?

Thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use netstat -ln | grep 514.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

I used nc and received this:
ss -lnt4p | grep 514
LISTEN 0 128 :514 *:
LISTEN 0 128 127.0.0.1:51490 :
LISTEN 0 128 :1514 *:

Does that mean I have listeners on both 514 and 1514?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...