Splunk Enterprise

How to Fix missing Forwarder issue. The MC "Rebuild Forwarder Assets" for 24 hours did not help! Thank u very much

SamHTexas
Builder

I used to clear all missing FWs in the Splunk Ent. using the MC "Rebuild" option. But it is not working anymore. Any helpful advice is much appreciated.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please elaborate on "did not help" and "is not working anymore".  What results do you get and what did you expect?

Please understand the "Rebuild Forwarder Assets" button does not fix anything.  It essentially tells the MC to forget forwarders it hasn't seen in a while so they're no longer "missing".  The forwarders are still gone, they're just not reported.  The true fix is to restart the forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Thank u for your message. I appreciate it as always. What I mean it the "rebuild forwarder assets" option did not reduce the number of missing FWs even by changing the duration. It stayed about 17. Usually this option would bring the number of the missing FWs down to 1 or 2. Thank u sir.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...