Splunk Enterprise

splunk instance not receiving data issue

pacifikn
Communicator

Hello Team,

hope you are doing well.

I really need your support to the issue ,I have experienced about logs not received from syslog sender devices 

into Splunk instance. before logs were received, but today no logs are coming, 

#I have checked splunk forwarders i found is running

also checked splunkd it is also running,

 

But also I found error but ii don't know if this is the root cause that cause this matter,

Below is the issue I found when I check the status, AND even when I do systemctl restart splunk-suf.service this doesn't work, still it gives me failed status!

bash-4.2$ systemctl status splunk-suf.service
* splunk-suf.service - splunk Universal Forwarder service
Loaded: loaded (/etc/systemd/system/splunk-suf.service; enabled; vendor preset:disabled)
Active: failed (Result: start-limit) since Sat 2021-09-25 11:28:14 CAT; 3min 3s ago
Process: 58723 ExecStart=/opt/splunkforwarder/bin/splunk _internal_launch_under_systemd --accept-license --no-prompt --answer-yes (code=exited, status=1, FAILURE)
Main PID: 58723 (code=exited, status=1/FAILURE)

***Kindly help me on how I may solve this issue and share with me the troubleshooting CLI commands to check why receiver Splunk instance are not receiving logs?

** I want to check also if the firewall is not blocking anything, what different command to use? 

Or any other advice that may help me to resolve this?

**MY OS: Centos, Splunk enterprise

Kindly help me on this matter, and share with me other command I can use to troubleshooting this and how i can fix this?

Thank you in advance.

 

Labels (1)
Tags (1)
0 Karma

sanjeev543
Communicator

Hi @pacifikn 
To start with can you check in splunkd.log (/opt/splunkforwarder/var/log/splunk/splunkd.log) and see what is happening when you start service? there may be several reasons for it's  failure also check if you have any filesystem full etc., 

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...