Splunk Enterprise

Heavy Forwarder missing

MakszimM
Engager

Hello!

We have a Splunk Cloud, for which we set up two on-prem components:
-Heavy forwarder( To route all file based logs through it as an intermediate forwarder to Splunk Cloud)
-Deployment server( To configure UF's)

 

We have downloaded the uf credential package, and set it up as an app, which we pushed it down to the heavy forwarder, to test if _internal logs appear, which they do, but I do not see the HF listed as a client on my Forwarder management page anymore.

Here comes the tricky part( if i delete a serverclass, the _internal logs disappear, so it still communicates, and i can see the deployment server listed if i push the command from HF: splunk show deploy-poll, but see nothing on DS if i push: 
splunk list deploy-clients


On the HF, deploymentclient.conf is configured correctly.

Any ideas?

Thanks!

Labels (3)
0 Karma

MakszimM
Engager

HF can communicate with DS , no network issues.

No UF's have been configured yet.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Look at your outputs.conf as I mentioned in my answer. This is the issue I think you are having.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@MakszimM - Do you see other UFs connected to Forwarder Management UI??

If no UFs and HF is visible then you need to fix this: (outputs.conf selective forwarding missing issue)

 

If the issue is only with HF then it might be Network connectivity related.

  • From HF to DS on 8089 port

 

I hope this helps!!! Kindly upvote if it does!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...