I upgraded the Heavy Forwarders in my environment to Splunk enterprise 8.2.5 and figured out today on the day of upgrade that I stopped receiving data in one of my indexes.
By searching events in the index prior to my upgrade, I was able to figure out that the host the events are being received from is running Windows 2008 R2 (running a Splunk UF version 7.2.2) - that may have something to do with this. I am trying to further troubleshoot and figure out how the data is being brought into that index but I am not a seasoned splunk veteran by any means.
Searching around for answers to this has been a bit convoluted. Could anyone help me through the process of tracking down how that data is being brought into that index? I'm thinking this may have something to do with lack of compatibility for HTTPS from the host to the heavy forwarder. Any help or guidance is much appreciated.
... View more