Monitoring Splunk

what is connection between forwarder and DS

Reethika
Path Finder

We noticed that a host "1234"  is not longer connecting with the DS. 

What does this mean? 

What would be the impact?

How do we troubleshoot this?

 Thanks.

 

 

Labels (2)
Tags (1)
0 Karma

anilchaithu
Builder

@Reethika 

If its not communicating, you can no longer deploy apps to the client. 

1) Does the client sending data to splunk indexer?

index=_internal host="client"

2) If yes, try to restart splunk service on the client

3) Is there any firewall between client & Deployment Server?

you can check this from DC doing telnet forwarderip:9997

4) if it checks out, please look for errors in the splunkd logs on the client .

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...