Getting Data In

Universal Forwarder stop Forwarding

jeanfrederic
New Member

Im using Splunk Cloud,

and every once in a while, im getting this error

05-13-2015 09:10:34.891 -0400 WARN TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 207000 seconds.

After that, my indexer is not indexing anymore.
Inside the log, I continue to see thing like this :

05-13-2015 09:07:16.757 -0400 WARN TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=516887 subOffset=1 on host=54.174.234.168:9997
05-13-2015 09:07:16.757 -0400 WARN TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=298120 subOffset=1 on host=54.174.234.168:9997

So I guess the forwarder continue to gather informations from differents servers.

I have to restart the service to make the cloud index again.

This universal forwarder is making WMI request to 30 differents server and push information to the cloud.
I have the exact same wmi.conf file on a "local test machine" wich is splunk enterprise 6.2.2 and it never stoped to index the same information.

Any one have the solution ? Thanks

0 Karma

jeanfrederic
New Member

For some reason, It turned to be my Universal Forwarder that was sending "duplicate" by itself.

My Splunk Enterprise Index was all right, around 2200 entries... and My Splunk Cloud was having 1 200 000 entries.
They both use the same wmi.conf

I dont know why I was having those duplicate.

0 Karma

Stefan
Explorer

How did you set your forwarder? Using a Deployment Manager?

Also what O/S is it running on? I've seen some similar behaviour on Windows forwarders in the past.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...