Splunk Enterprise

Heavy Forwarder missing

MakszimM
Engager

Hello!

We have a Splunk Cloud, for which we set up two on-prem components:
-Heavy forwarder( To route all file based logs through it as an intermediate forwarder to Splunk Cloud)
-Deployment server( To configure UF's)

 

We have downloaded the uf credential package, and set it up as an app, which we pushed it down to the heavy forwarder, to test if _internal logs appear, which they do, but I do not see the HF listed as a client on my Forwarder management page anymore.

Here comes the tricky part( if i delete a serverclass, the _internal logs disappear, so it still communicates, and i can see the deployment server listed if i push the command from HF: splunk show deploy-poll, but see nothing on DS if i push: 
splunk list deploy-clients


On the HF, deploymentclient.conf is configured correctly.

Any ideas?

Thanks!

Labels (3)
0 Karma

MakszimM
Engager

HF can communicate with DS , no network issues.

No UF's have been configured yet.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Look at your outputs.conf as I mentioned in my answer. This is the issue I think you are having.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Do you see other UFs connected to Forwarder Management UI??

If no UFs and HF is visible then you need to fix this: (outputs.conf selective forwarding missing issue)

 

If the issue is only with HF then it might be Network connectivity related.

  • From HF to DS on 8089 port

 

I hope this helps!!! Kindly upvote if it does!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...