Getting Data In

Universal Forwarder for Mac not resuming sending when using PersistentQueue

francisaugusto
New Member

I have tried two input modes: monitor and tcp. When I use the monitor mode and read text files, the data sending from the Universal Forwarder resumes in case the network connectivity gets lost.

However, when I use tcp as an input and a persistent queue, I see that the queue grows while there is no connectivity (for example, if I turn wifi off). When turning the connection on again, the persistent queue remains growing and no data is actually sent to the server.

I have to restart Splunk so that the sending resumes. The restarting takes a few minutes - not the case with the monitor mode - and when it finally restarts, the persistent queue is erased and the data that was saved there doesn't get sent. 

Is there a major bug with the universal forwarder?

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...