Getting Data In

Splunk Alert: Forwarder Offline is sending an alert every hour

New Member

Splunk Alert: Forwarder Offline is sending an alert every hour however the SplunkForwarder is not offline. Please help how could i get rid of this alert (Splunk Alert: Forwarder Offline )

The alert condition for 'Forwarder Offline' was triggered.

Instance Type Version OS Architecture Status Last Connected to Indexers Total KB Average KB/s Over Time Average KB/s Average Events/s
DXX-DC03 Universal Forwarder 6.3.3 Windows x64 missing N/A N/A N/A N/A

Thanks in advance for the help.

0 Karma

Contributor

Hi @afawad,
Can you try rebuilding your forwarder asset table in your deployment server.
Click rebuild forwarder assets in Monitoring Console > Settings > Forwarder Monitoring Setup.
You can check below splunk docs as well.
https://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Configureforwardermonitoring

0 Karma

New Member

You have shared the link for Splunk enterprise but I am having an issue with UF.

0 Karma

Champion

Hi afawad,

Could you please share the splunk search you used for this alert?

0 Karma