Splunk Enterprise

Heavy Forwarder missing

MakszimM
Engager

Hello!

We have a Splunk Cloud, for which we set up two on-prem components:
-Heavy forwarder( To route all file based logs through it as an intermediate forwarder to Splunk Cloud)
-Deployment server( To configure UF's)

 

We have downloaded the uf credential package, and set it up as an app, which we pushed it down to the heavy forwarder, to test if _internal logs appear, which they do, but I do not see the HF listed as a client on my Forwarder management page anymore.

Here comes the tricky part( if i delete a serverclass, the _internal logs disappear, so it still communicates, and i can see the deployment server listed if i push the command from HF: splunk show deploy-poll, but see nothing on DS if i push: 
splunk list deploy-clients


On the HF, deploymentclient.conf is configured correctly.

Any ideas?

Thanks!

Labels (3)
0 Karma

MakszimM
Engager

HF can communicate with DS , no network issues.

No UF's have been configured yet.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Look at your outputs.conf as I mentioned in my answer. This is the issue I think you are having.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Do you see other UFs connected to Forwarder Management UI??

If no UFs and HF is visible then you need to fix this: (outputs.conf selective forwarding missing issue)

 

If the issue is only with HF then it might be Network connectivity related.

  • From HF to DS on 8089 port

 

I hope this helps!!! Kindly upvote if it does!!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...