Getting Data In

Splunk Alert: Forwarder Offline is sending an alert every hour

afawad
New Member

Splunk Alert: Forwarder Offline is sending an alert every hour however the SplunkForwarder is not offline. Please help how could i get rid of this alert (Splunk Alert: Forwarder Offline )

The alert condition for 'Forwarder Offline' was triggered.

Instance Type Version OS Architecture Status Last Connected to Indexers Total KB Average KB/s Over Time Average KB/s Average Events/s
DXX-DC03 Universal Forwarder 6.3.3 Windows x64 missing N/A N/A N/A N/A

Thanks in advance for the help.

0 Karma

nikita_p
Contributor

Hi @afawad,
Can you try rebuilding your forwarder asset table in your deployment server.
Click rebuild forwarder assets in Monitoring Console > Settings > Forwarder Monitoring Setup.
You can check below splunk docs as well.
https://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureforwardermonitoring

0 Karma

afawad
New Member

You have shared the link for Splunk enterprise but I am having an issue with UF.

0 Karma

p_gurav
Champion

Hi afawad,

Could you please share the splunk search you used for this alert?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...