We have a daily scheduled report which is to be generated at 12pm for every day, the issue we are facing is the data isn't getting in. In order to make data flow, we are currently restarting the services on forwarders, but its a temporary solution. Can we have a permanent solution to fix this? Help me out in knowing what to do. Thanks in advance.
Keeping the forwarders up is a true challenge. We try to figure out why the splunk service goes down, whether it's a crash and if so why. Adhering to the forwarders' ulimit best practices is important and having bootstart for all the forwarders.
splunk that we are running is of version 6.2 , is that we need to change in config files , why this is occurring very frequently , as it is down today even , we restarted the services and now running fine. but i think restarting the services frequently may effect other apps and searches. can any one help in this !