Hi,
multiple Forwarders stops sending data for no reason for every 20 days , but when a restart is done, all starts sending normally. there are no warning or error logs in splunkd either. not sure what's causing the issue.
This issue is happening on same forwarders every time.
Hi @raghu0463,
maybe the stop sending is from the 1st until the 12nd of the month?
if this is true, please check the timestamp format that probably is in european format (dd/mm/yyyy) and Splunk reads in american format (mm/dd/yyyy).
Ciao.
Giuseppe
Can you give some more information to us to help you? Like inputs, splunk and os version, have it works earlier etc.