Somehow i have not got logs from universal forwarder servers since Sep 11, How to find out the reason ?
read here all the way through:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Cantfinddata
@andydong ,
Is it from all servers or only few? Hows your deployment architecture looks like?(IDC,standalone,HFs)
First of all , check in the logs of forwarders to see if there are any connection error.