Getting Data In

Heavy Forwarder not receiving logs

vnguyen46
Contributor

Hi,
After migrated Splunk Enterprise to a new hardware, my HFs stop receiving logs over port 514/1514. It's verified these ports are open on the new HFs. The new system is receiving logs from UFs running on Windows and from Cloud-based (AWS).

What other configuration needs to be done like syslog daemon or any things else for the new HFs to receive logs being sent over port 514/1514 like F5 and other network devices?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the ports have a listener on them. Check your firewall(s) to ensure connectivity.
If the HF moved to a new address, make sure all clients have that address.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Don't you think I need to configure the daemon syslog on the new HFs so they can receive the logs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you absolutely need to do that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Hi Richgalloway,

I'd like to circle back on HFs stopped receiving logs. All logs were once received well after system admin fixed the daemon log. Then last Thursday, HFs suddenly stopped receiving 9 out of 10 logs at almost same time. There is no issue with new logs. Disk space and network connection are not the cause.

Would you please share what you think?

Thank you,

0 Karma

vnguyen46
Contributor

"Verify the ports have a listener on them" - would you please give more details on this?

Thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use netstat -ln | grep 514.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

I used nc and received this:
ss -lnt4p | grep 514
LISTEN 0 128 :514 *:
LISTEN 0 128 127.0.0.1:51490 :
LISTEN 0 128 :1514 *:

Does that mean I have listeners on both 514 and 1514?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...