Splunk Enterprise

UF Logs Sent to Indexer but cannot be seen in Forwarder Management

zekiramhi
Path Finder

Hello,

During the health checkup period of our uf connectors, mainly Linux OS's have been seen as sending logs to indexers parsed correctly but cannot be seen when the same host is searched in the Deployment Server's "Forwarder Management" page.

A couple of notes to follow up with here:

1. Connections to the deployment server are allowed and seen as traffic is going from the uf to the deployment server without interference

2. No duplicate GUIDs are found relating to the specified hosts

What are some other recommendations to troubleshoot this issue?

Thanks,

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Check the forwarders logs to make sure they're able to phone home successfully.  Look for "DC:" events.

Make sure the forwarders have a deploymentclient.conf file that references the correct DS.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the forwarders logs to make sure they're able to phone home successfully.  Look for "DC:" events.

Make sure the forwarders have a deploymentclient.conf file that references the correct DS.

---
If this reply helps you, Karma would be appreciated.
0 Karma

zekiramhi
Path Finder

After checking the splunkd logs for all the machines with the same situation, they all had the same following message in the logs concerning DC:

DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected

deploymentclient.conf also seems to be pointing to the correct DNS name for the deployment server. I assume there is a DNS problem here that happenned After the initial setup was made, will checkup with the server owners. But until then, thank you for the input.

Best Regards,

0 Karma

zekiramhi
Path Finder

Thank you for the recommendations, I have requested the specific log files to proceed with the investigation.

Will reply back as soon as the research has been completed.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...