Getting Data In

Removing unsent messages of Splunk universal forwarder

manasbellani
Explorer

Hi, I have a simple setup of a Splunk universal forwarder on a windows server forwarding data to a single Linux server acting as Splunk indexer/search head. 

Sometimes the connection to this server can drop from the windows box and when it is restored, a large number of messages not sent when the connection had dropped get forwarded.

How can I empty the Splunk universal forwarder messages queue via the command line just before the connection is reinstated, so that any unsent messages are dropped?

Labels (1)
0 Karma
1 Solution

tscroggins
Champion

@manasbellani 

To prevent the forwarder from queuing events and blocking output, you can add the blockOnCloning setting to outputs.conf. On a typical unmanaged Windows forwarder, modify C:\Program Files\SplunkUniversalForwarder\etc\sytem\local\outputs.conf and restart the "SplunkForwarder Service" service.

[tcpout]
blockOnCloning = false

This setting will result in dropped/lost/missing events any time the forwarder is unable to connect to the receiver and output queues are filled. Implement with caution!

View solution in original post

tscroggins
Champion

@manasbellani 

To prevent the forwarder from queuing events and blocking output, you can add the blockOnCloning setting to outputs.conf. On a typical unmanaged Windows forwarder, modify C:\Program Files\SplunkUniversalForwarder\etc\sytem\local\outputs.conf and restart the "SplunkForwarder Service" service.

[tcpout]
blockOnCloning = false

This setting will result in dropped/lost/missing events any time the forwarder is unable to connect to the receiver and output queues are filled. Implement with caution!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...