Splunk Enterprise

splunk instance not receiving data issue

pacifikn
Communicator

Hello Team,

hope you are doing well.

I really need your support to the issue ,I have experienced about logs not received from syslog sender devices 

into Splunk instance. before logs were received, but today no logs are coming, 

#I have checked splunk forwarders i found is running

also checked splunkd it is also running,

 

But also I found error but ii don't know if this is the root cause that cause this matter,

Below is the issue I found when I check the status, AND even when I do systemctl restart splunk-suf.service this doesn't work, still it gives me failed status!

bash-4.2$ systemctl status splunk-suf.service
* splunk-suf.service - splunk Universal Forwarder service
Loaded: loaded (/etc/systemd/system/splunk-suf.service; enabled; vendor preset:disabled)
Active: failed (Result: start-limit) since Sat 2021-09-25 11:28:14 CAT; 3min 3s ago
Process: 58723 ExecStart=/opt/splunkforwarder/bin/splunk _internal_launch_under_systemd --accept-license --no-prompt --answer-yes (code=exited, status=1, FAILURE)
Main PID: 58723 (code=exited, status=1/FAILURE)

***Kindly help me on how I may solve this issue and share with me the troubleshooting CLI commands to check why receiver Splunk instance are not receiving logs?

** I want to check also if the firewall is not blocking anything, what different command to use? 

Or any other advice that may help me to resolve this?

**MY OS: Centos, Splunk enterprise

Kindly help me on this matter, and share with me other command I can use to troubleshooting this and how i can fix this?

Thank you in advance.

 

Labels (1)
Tags (1)
0 Karma

sanjeev543
Communicator

Hi @pacifikn 
To start with can you check in splunkd.log (/opt/splunkforwarder/var/log/splunk/splunkd.log) and see what is happening when you start service? there may be several reasons for it's  failure also check if you have any filesystem full etc., 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...