...p and running?
In case data are recovered after the forwarder restore, I suppose they are stored in the forwarder queue. Which limits this queue have? What is his size? Will be able to ingest all data...
Hello Community,
I am having issues connecting my Universal Forwarder with a Heavy Forwarder.
I have the following set up: UF-->HF-->IDx
I can see the logs from HF to IDx, but not sure w...
Hello! When I updated my Splunk Universal Forwarder, my data stopped sending data into Splunk. I do not know how to find the upgraded Splunk servers tcpout address I need to update in the S...
I have configured Heavy Forwarder to collect and forward syslog data to our Splunk Indexers. We purposely don't wish to use syslog server for the log collection due to other reasons. Now we also h...
...nd it gets more and more confused: https://www.splunk.com/en_us/resources/videos/splunk-cloud-tutorial.html https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-to-forward-data...
...as paused the data flow. Forwarding to host_dest=<indexer_ip> inside output group default-autolb-group from host_src=<UF_server_hostname> has been blocked” which appears to be relevant....
I am trying to implement a simple Splunk system on my local computer to learn a bit about how you set up forwards and get data into Splunk. I am running Splunk Enterprise on a CentOS 8 v...
...nstalled on the syslog server, it forwards data to splunk IF I configure it
correctly. I have tried configuring the Splunk receiver two ways: one using the "Forwarding and receiving" option f...
Hello all,
I have a working universal forwarder that happily sends data to my Enterprise indexer.
The data shows up under the forwarder's hostname on the indexer.
I would like to have a c...