Getting Data In

Is forwarder inactive and how can I check?

JGP
Explorer

If there is no file update for a quite long time and later then is update in the file, then only after forwarder service restarts then it pushes the new data. Is forwarder is inactive as there was no update since. 

what is default duration for forwarder being inactive? any suggestion or is it documented

Labels (2)
0 Karma

JGP
Explorer

@woodcock , forwarder service was running and after service restart only data started flowing

0 Karma

woodcock
Esteemed Legend

This is not at all normal UF behavior so I suspect that the UF was not running and the "restart" was actually a "start".

JGP
Explorer

hi @gcusello 

thanks for quick response.

So forwarder will never be inactive if there is no update in the file say for more than 20/30days and still will be able to see internal logs and if the re is an update after that time it should data without service restart

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

yes, Universal Forwarder continously sends its internal logs that you can check, even if there isn't any data to forward.

Ciao.

Giuseppe

0 Karma

JGP
Explorer

Yes, understands that it will wait for new data. But if there is no new data for a quite a long time so will forwarder be inactive and stop internal logs as well. So if there new data it is not flowing currently and after service restarts able to see data. What could be reason for this?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

Forwarder's internal logs should never stop, if there's a pause there could be some other issue.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JGP,

Forwarders are always waiting for data to read and forward.

If you don't receive data is because there isn't any new data.

You can check if the Forwarder us up and running checking the the presence of Splunk internal logs:

index=_internal host=your_forwarder

I always create an alert that make this check because if a Forwarder is down you're blind.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...