If there is no file update for a quite long time and later then is update in the file, then only after forwarder service restarts then it pushes the new data. Is forwarder is inactive as there was no update since.
what is default duration for forwarder being inactive? any suggestion or is it documented
@woodcock , forwarder service was running and after service restart only data started flowing
This is not at all normal UF behavior so I suspect that the UF was not running and the "restart" was actually a "start".
hi @gcusello
thanks for quick response.
So forwarder will never be inactive if there is no update in the file say for more than 20/30days and still will be able to see internal logs and if the re is an update after that time it should data without service restart
Hi @JGP,
yes, Universal Forwarder continously sends its internal logs that you can check, even if there isn't any data to forward.
Ciao.
Giuseppe
Yes, understands that it will wait for new data. But if there is no new data for a quite a long time so will forwarder be inactive and stop internal logs as well. So if there new data it is not flowing currently and after service restarts able to see data. What could be reason for this?
Hi @JGP,
Forwarder's internal logs should never stop, if there's a pause there could be some other issue.
Ciao.
Giuseppe
Hi @JGP,
Forwarders are always waiting for data to read and forward.
If you don't receive data is because there isn't any new data.
You can check if the Forwarder us up and running checking the the presence of Splunk internal logs:
index=_internal host=your_forwarder
I always create an alert that make this check because if a Forwarder is down you're blind.
Ciao.
Giuseppe