Hello,
we have problem with useACK, there are known bugs with our UF 7.3.4 : https://docs.splunk.com/Documentation/Splunk/7.3.4/ReleaseNotes/KnownIssues : SPL-171178, SPL-167307, SPL-202078
Disabling indexer ack from forwarder is not acceptable in our case so which solution is best? Schedule regular restarts? Downgrade?
Thanks for your contributions.
Hi
Probably there is no good solution to this until Splunk will fix it (seems to be still on 8.2.2).
Is this useACK needed for all your events or only some? If later then maybe you could use two set of UF as they propose? But probably you must do those regular restarts or even downgrade.
https://www.splunk.com/en_us/legal/splunk-software-support-policy.html tells that UFs have 60 month support period. If I look right 7.3 has released Version 7.3. was released on July 31, 2019. Based on that it's still supported. So maybe the best option is downgrade it where it's needed.
Anyhow try to push Splunk to fix this issue.
r. Ismo
Thanks, this is not acceptable to disable useACK 😐