Getting Data In

Heavy forwarder - Doesn't show/forward events

rahiparikh
Explorer

Hi,

I installed a heavy forwarder on a box and, after a while, I found out that license was not working. ( By mistake, I forgot to change the license type to forwarder and instead ran it under enterprise trial license. )

Indexer name            server-name
License expiration      xxx x, xxxx 4:00:04 AM
Licensed daily volume   1 MB
Volume used today       0 MB (0% of quota)
Warning count           0

So, I contacted splunk and got the reset license and applied it. But, now after reboot I get the same message and my data doesn't show up in indexer. I am sure that they have an established connection because when I check for open ports they have a live connection.

Don't know what problem could be. Any idea? Thanks!

0 Karma
1 Solution

Simeon
Splunk Employee
Splunk Employee

It sounds like forwarding is not enabled or working. You should run the following search on the indexer to see if it has even connected:

index=_internal source=*metrics.log tcpin_connections | timechart count by sourceIp

If there are no events, then it is likely your forwarder is not configured properly. you should then examine your outputs.conf settings and inputs.conf settings.

View solution in original post

Simeon
Splunk Employee
Splunk Employee

It sounds like forwarding is not enabled or working. You should run the following search on the indexer to see if it has even connected:

index=_internal source=*metrics.log tcpin_connections | timechart count by sourceIp

If there are no events, then it is likely your forwarder is not configured properly. you should then examine your outputs.conf settings and inputs.conf settings.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...