Getting Data In

How to troubleshoot Complex Heavy Forwarder Flows

ekenne06
Path Finder

Hey Splunkers! i've inherited a Splunk deployment that utilizes multiple heavy forwarders that uses TCP Routing and several tcpout groups to send data to different locations. One of the issues i'm running into is most of the orginal team that deployed has left and there is little documentation. What is the best way to troubleshoot some of these flows? 

 

Right now i'm using tcpdump on the specific inputs/outputs ports and using that to built myself a visio diagram of the flows. Is this the best approach or are there other utilities I could use? I'm currently running 7.3.3

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...