Hi Actually we are forwarding data from 2 forwarders servers to the indexer server, from one forwarder server we are receiving the data in indexer server and in search head also we can see data but we are not receiving the data in indexer server from other forwarder server. Even in the forwarder server logs we can see it is connected to indexer but logs are not getting forward to the indexer server. We can see below logs in splunkd as below 12-07-2020 12:38:07.059 +0100 INFO TcpOutputProc - Connected to idx=xx.xx.xx.xx:9998, pset=0, reuse=0. 12-07-2020 12:38:07.091 +0100 INFO WatchedFile - Will begin reading at offset=20396720 for file='E:\Apps\SplunkUniversalForwarder\var\log\splunk\metrics.log'. 12-07-2020 12:38:07.106 +0100 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='E:\Apps\SplunkUniversalForwarder\var\log\splunk\license_usage.log'. 12-07-2020 12:38:07.153 +0100 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='E:\Apps\SplunkUniversalForwarder\var\log\splunk\remote_searches.log'. Below log can see in helat.log TCPOutAutoLB-0 - More than 70% of forwarding destinations have failed Outputs.conf file [tcpout] defaultGroup = lb [tcpout:lb] server =xxx.xxx.com:9998 autoLB = true
... View more