Splunk Enterprise

splunk instance not receiving data issue

pacifikn
Communicator

Hello Team,

hope you are doing well.

I really need your support to the issue ,I have experienced about logs not received from syslog sender devices 

into Splunk instance. before logs were received, but today no logs are coming, 

#I have checked splunk forwarders i found is running

also checked splunkd it is also running,

 

But also I found error but ii don't know if this is the root cause that cause this matter,

Below is the issue I found when I check the status, AND even when I do systemctl restart splunk-suf.service this doesn't work, still it gives me failed status!

bash-4.2$ systemctl status splunk-suf.service
* splunk-suf.service - splunk Universal Forwarder service
Loaded: loaded (/etc/systemd/system/splunk-suf.service; enabled; vendor preset:disabled)
Active: failed (Result: start-limit) since Sat 2021-09-25 11:28:14 CAT; 3min 3s ago
Process: 58723 ExecStart=/opt/splunkforwarder/bin/splunk _internal_launch_under_systemd --accept-license --no-prompt --answer-yes (code=exited, status=1, FAILURE)
Main PID: 58723 (code=exited, status=1/FAILURE)

***Kindly help me on how I may solve this issue and share with me the troubleshooting CLI commands to check why receiver Splunk instance are not receiving logs?

** I want to check also if the firewall is not blocking anything, what different command to use? 

Or any other advice that may help me to resolve this?

**MY OS: Centos, Splunk enterprise

Kindly help me on this matter, and share with me other command I can use to troubleshooting this and how i can fix this?

Thank you in advance.

 

Labels (1)
Tags (1)
0 Karma

sanjeev543
Communicator

Hi @pacifikn 
To start with can you check in splunkd.log (/opt/splunkforwarder/var/log/splunk/splunkd.log) and see what is happening when you start service? there may be several reasons for it's  failure also check if you have any filesystem full etc., 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...