Getting Data In

Heavy forwarder not sending logs (Windows)

hkizuka
Explorer

I've got an issue with HF not sending the logs to indexer.
Does anyone have experience with something like this?

HF was sending the log to indexer as it should until yesterday.
at one moment, indexer OS somehow got shutdown and HF didn't send any logs including internal logs even after the indexer was booted and connection was established.

HF:Windows Server 2012
indexer:Windows Server 2016
Splunk version : 6.6.3

when I checked splunkd.log in HF, I saw logs written as below


10-27-2017 09:07:18.938 +0900 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group splunk01 has been blocked for 49250 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.
10-27-2017 09:07:22.168 +0900 INFO TcpOutputProc - Removing quarantine from idx=xxx.xxx.xxx.xxx:9997
10-27-2017 09:07:22.199 +0900 INFO TcpOutputProc - Connected to idx=xxx.xxx.xxx.xxx:9997, pset=0, reuse=0.
10-27-2017 09:07:22.714 +0900 INFO TailReader - ...continuing.
10-27-2017 09:07:22.885 +0900 INFO LMStackMgr - should rollover=true because _lastRolloverTime=1508943600 lastRolloverDay=1508943600 snappedNow=1509030000
10-27-2017 09:07:22.901 +0900 INFO LMStackMgr - finished rollover, new lastRolloverTime=1509062842


it seems like HF did not read the new log file which it should.
after i reboot the HF splunkd, it started to send all logs again.

does anyone have any idea for the work-around other than rebooting HF's splunkd?

0 Karma

peterchenadded
Path Finder

Did you try reloading the inputs?

./splunk _internal call /services/data/inputs/monitor/_reload -auth admin:changeme

It might help.

0 Karma

hkizuka
Explorer

thanks! i'll try when it happens again!

0 Karma

koshyk
Super Champion

are you connected to your Indexers directly or using indexerDiscovery?

0 Karma

hkizuka
Explorer

looking at the indexer directly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...