Getting Data In

Splunk Alert: Forwarder Offline is sending an alert every hour

afawad
New Member

Splunk Alert: Forwarder Offline is sending an alert every hour however the SplunkForwarder is not offline. Please help how could i get rid of this alert (Splunk Alert: Forwarder Offline )

The alert condition for 'Forwarder Offline' was triggered.

Instance Type Version OS Architecture Status Last Connected to Indexers Total KB Average KB/s Over Time Average KB/s Average Events/s
DXX-DC03 Universal Forwarder 6.3.3 Windows x64 missing N/A N/A N/A N/A

Thanks in advance for the help.

0 Karma

nikita_p
Contributor

Hi @afawad,
Can you try rebuilding your forwarder asset table in your deployment server.
Click rebuild forwarder assets in Monitoring Console > Settings > Forwarder Monitoring Setup.
You can check below splunk docs as well.
https://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureforwardermonitoring

0 Karma

afawad
New Member

You have shared the link for Splunk enterprise but I am having an issue with UF.

0 Karma

p_gurav
Champion

Hi afawad,

Could you please share the splunk search you used for this alert?

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...