Getting Data In

Heavy Forwarder Kept sending logs after splunk was uninstalled from host.

tbyrne15
New Member

The only explanation I could think was that it was not uninstalled properly or it was over riding data somehow or it is was backlog?

If anyone has any idea what it might could be helpful thank you!

0 Karma

solarboyz1
Builder

Do you see any Splunk process running ? Do you see any splunk process holding any files/IO open?
Have you rebooted the system since the uninstall? Do you still see connection from the old heavy forwarder to the indexers?

Are there other heavy forwarders the data could be coming from?

If the inputs.conf has the wrong hostname, the events will appear to be from a different host. This can happen when images are cloned.

The same is true for the GUID, if you are seeing license usage ensure there isn't another host using the same GUID.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...