Hi All,
Good day, would like to seek for help regarding on our universal forwarders. Some of our sources (universal forwarder) intermittently stops forwarding logs. I don't know why, firewall definition is intact, if you telnet splunk ports from the sources, the results are good. However, when checking splunkd.log , Cooked Connection, Raw Connection, Ping connection and Connection TIme out can be seen. Please help. Thanks.
Universal Forwarder Versions are:
6.2.6, 6.4.0
Splunk Enterprise Infra and versions:
6 Indexers: 6.6.1
3 Heavy Forwarders: 6.6.1
2 SH: 6.6.1
Regards,
Dan
... View more