Hi everyone ,
We have issue with Splunk universal forwarders , we installed recently on SQl servers , i have all inputs.conf and outputs.conf set correctly and there is no error in log data . but its no reporting logs in splunk. Ours is clustered search head pool with 2 search heads , 5 indexers and 5 heavy forwarders . we have forward management console , which generally phone-in to the universal forwarders by pushing some of the apps . In Past i have some other VM's which i faced the same issue , i reinstalled the universal forwarder agent which fixed the issue , but currently its not happening with these SQL servers .
Thanks in advance
Hi Koushik_Katta,
just a few stupid questions:
did you installed forwarders from scratch or did you cloned it from another installation?
in both the cases check if hostname in $SPLUNK_HOME/etc/system/local/server.conf and $SPLUNK_HOME/etc/system/local/inputs.conf is correct.
have you Splunk internal log files from these forwarders?
if not the problem is connection betwen forwarders and indexers.
If yes check log policies on your SQL Server and then TA that you're using to take logs.
Bye.
Giuseppe
Hi Koushik_Katta,
just a few stupid questions:
did you installed forwarders from scratch or did you cloned it from another installation?
in both the cases check if hostname in $SPLUNK_HOME/etc/system/local/server.conf and $SPLUNK_HOME/etc/system/local/inputs.conf is correct.
have you Splunk internal log files from these forwarders?
if not the problem is connection betwen forwarders and indexers.
If yes check log policies on your SQL Server and then TA that you're using to take logs.
Bye.
Giuseppe
hi Cusello ,
did you installed forwarders from scratch or did you cloned it from another installation?
yes i did it from scratch , installed manually
in both the cases check if hostname in $SPLUNK_HOME/etc/system/local/server.conf and $SPLUNK_HOME/etc/system/local/inputs.conf is correct
host name is correct in both .conf's
have you Splunk internal log files from these forwarders?
yes
if not the problem is connection betwen forwarders and indexers.
this i'm not sure , i think there wouldn't be connection issues , its working for other agents