We are trying to replace our current indexer with two new indexers. We made updates in outputs.conf to reflect the new servers. We ran a deployment to initiate the change and after the deployment all of our windows forwarders were fine and showed up, but we are no longer receiving data from any of our unix forwarders and we are not sure why? - We re-deployed our original configuration for the time being until we can work out our issue.
I reviewed the splunk logs and the unix configuration and it looks like that the splunk forwarders were never restarted after the deployment of the configuration files. Anyone know how I can check what the reason is that the splunk forwarders were never resstarted? Would that vbe on the deploymnet server logs or on teh forwarders themselves?
I would run this on one of the servers having the issue after you try and make the change on that host. And restart splunk. See if it still shows old value. If so you likely have another outputs.conf taking precedence somewhere.
/splunk btool outputs list