Splunk Alert: Forwarder Offline is sending an alert every hour however the SplunkForwarder is not offline. Please help how could i get rid of this alert (Splunk Alert: Forwarder Offline )
The alert condition for 'Forwarder Offline' was triggered.
Instance Type Version OS Architecture Status Last Connected to Indexers Total KB Average KB/s Over Time Average KB/s Average Events/s
DXX-DC03 Universal Forwarder 6.3.3 Windows x64 missing N/A N/A N/A N/A
Thanks in advance for the help.
Hi @afawad,
Can you try rebuilding your forwarder asset table in your deployment server.
Click rebuild forwarder assets in Monitoring Console > Settings > Forwarder Monitoring Setup.
You can check below splunk docs as well.
https://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureforwardermonitoring
You have shared the link for Splunk enterprise but I am having an issue with UF.
Hi afawad,
Could you please share the splunk search you used for this alert?