Hi Splunker;
In initial the connect between deployment server and windows forwarder is good and splunk receiving logs from it.
Then occurred losing connect from it, and I check to splunkforwarder status, the splunkforwarder status is stropped and check ports the ports is open, and I executed (splunk start) command appeared the following error:
(Timed out waiting for splunkd to start).
And some times the splunk agent service suddenly stopped in windows devices and I must execute the splunk start command for run, this case is always repeated, please I need your advise in that.
Regards;
on the forwarder do to the splunkd.log and look for errors or crashes.
also look for crash.log in the same spot
in windows its most likely at:
C:\Program Files\SplunkUniversalForwarder\var\log\splunk