Getting Data In

Is forwarder inactive and how can I check?

JGP
Explorer

If there is no file update for a quite long time and later then is update in the file, then only after forwarder service restarts then it pushes the new data. Is forwarder is inactive as there was no update since. 

what is default duration for forwarder being inactive? any suggestion or is it documented

Labels (2)
0 Karma

JGP
Explorer

@woodcock , forwarder service was running and after service restart only data started flowing

0 Karma

woodcock
Esteemed Legend

This is not at all normal UF behavior so I suspect that the UF was not running and the "restart" was actually a "start".

JGP
Explorer

hi @gcusello 

thanks for quick response.

So forwarder will never be inactive if there is no update in the file say for more than 20/30days and still will be able to see internal logs and if the re is an update after that time it should data without service restart

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

yes, Universal Forwarder continously sends its internal logs that you can check, even if there isn't any data to forward.

Ciao.

Giuseppe

0 Karma

JGP
Explorer

Yes, understands that it will wait for new data. But if there is no new data for a quite a long time so will forwarder be inactive and stop internal logs as well. So if there new data it is not flowing currently and after service restarts able to see data. What could be reason for this?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

Forwarder's internal logs should never stop, if there's a pause there could be some other issue.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

Forwarders are always waiting for data to read and forward.

If you don't receive data is because there isn't any new data.

You can check if the Forwarder us up and running checking the the presence of Splunk internal logs:

index=_internal host=your_forwarder

I always create an alert that make this check because if a Forwarder is down you're blind.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...