Getting Data In

Universal Forwarder resending event log data

splunkjas1
Path Finder

If the IP address for a host changes or if it gets a new GUID, would the forwarder resend the entire Windows event log?

0 Karma
1 Solution

nickhills
Ultra Champion

It depends.
If you uninstalled the old forwarder and then reinstalled the new one, it’s quite possible that it will re-read and send all the logs.

If you upgraded the forwarder this should not occurr, even if the ip or guild changes.

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

It depends.
If you uninstalled the old forwarder and then reinstalled the new one, it’s quite possible that it will re-read and send all the logs.

If you upgraded the forwarder this should not occurr, even if the ip or guild changes.

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

I noted “possible” because depending on your config, it may elect to only send evens which are older than x days, or in the case of windows events, only while the forwarder is running. Neither of these are default config, and have drawbacks.

If my comment helps, please give it a thumbs up!
0 Karma

somesoni2
Revered Legend

Is your forwarder resending event logs again? Has any specific activity was performed on your UF like version upgrade?

0 Karma

splunkjas1
Path Finder

The forwarders are resending event logs. We upgraded them from 6.4.4 to 6.4.9. Would the upgrade cause logs to be resent?

0 Karma

somesoni2
Revered Legend

It should'nt. How did you do the upgrade (procedure)? Was it it inline with what this Splunk documentation suggests?
https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/UpgradetheWindowsuniversalforwarder#...

0 Karma

splunkjas1
Path Finder

I asked the folks who performed the upgrade and they told me they do uninstall the 6.4.4 version before installing 6.4.9. So that's probably what caused the logs to be resent, would you agree?

0 Karma

nickhills
Ultra Champion

Yes. In that case I would say it’s expected behaviour

If my comment helps, please give it a thumbs up!
0 Karma

splunkjas1
Path Finder

Okay, thank you.

0 Karma

nickhills
Ultra Champion

I converted my comment to an answer, so you can accept it if it helped

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...