Getting Data In

Removing unsent messages of Splunk universal forwarder

manasbellani
Explorer

Hi, I have a simple setup of a Splunk universal forwarder on a windows server forwarding data to a single Linux server acting as Splunk indexer/search head. 

Sometimes the connection to this server can drop from the windows box and when it is restored, a large number of messages not sent when the connection had dropped get forwarded.

How can I empty the Splunk universal forwarder messages queue via the command line just before the connection is reinstated, so that any unsent messages are dropped?

Labels (1)
0 Karma
1 Solution

tscroggins
Influencer

@manasbellani 

To prevent the forwarder from queuing events and blocking output, you can add the blockOnCloning setting to outputs.conf. On a typical unmanaged Windows forwarder, modify C:\Program Files\SplunkUniversalForwarder\etc\sytem\local\outputs.conf and restart the "SplunkForwarder Service" service.

[tcpout]
blockOnCloning = false

This setting will result in dropped/lost/missing events any time the forwarder is unable to connect to the receiver and output queues are filled. Implement with caution!

View solution in original post

tscroggins
Influencer

@manasbellani 

To prevent the forwarder from queuing events and blocking output, you can add the blockOnCloning setting to outputs.conf. On a typical unmanaged Windows forwarder, modify C:\Program Files\SplunkUniversalForwarder\etc\sytem\local\outputs.conf and restart the "SplunkForwarder Service" service.

[tcpout]
blockOnCloning = false

This setting will result in dropped/lost/missing events any time the forwarder is unable to connect to the receiver and output queues are filled. Implement with caution!

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...