Getting Data In

Universal Forwarder stop Forwarding

jeanfrederic
New Member

Im using Splunk Cloud,

and every once in a while, im getting this error

05-13-2015 09:10:34.891 -0400 WARN TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 207000 seconds.

After that, my indexer is not indexing anymore.
Inside the log, I continue to see thing like this :

05-13-2015 09:07:16.757 -0400 WARN TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=516887 subOffset=1 on host=54.174.234.168:9997
05-13-2015 09:07:16.757 -0400 WARN TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=298120 subOffset=1 on host=54.174.234.168:9997

So I guess the forwarder continue to gather informations from differents servers.

I have to restart the service to make the cloud index again.

This universal forwarder is making WMI request to 30 differents server and push information to the cloud.
I have the exact same wmi.conf file on a "local test machine" wich is splunk enterprise 6.2.2 and it never stoped to index the same information.

Any one have the solution ? Thanks

0 Karma

jeanfrederic
New Member

For some reason, It turned to be my Universal Forwarder that was sending "duplicate" by itself.

My Splunk Enterprise Index was all right, around 2200 entries... and My Splunk Cloud was having 1 200 000 entries.
They both use the same wmi.conf

I dont know why I was having those duplicate.

0 Karma

Stefan
Explorer

How did you set your forwarder? Using a Deployment Manager?

Also what O/S is it running on? I've seen some similar behaviour on Windows forwarders in the past.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...