Getting Data In

Heavy Forwarder not receiving logs

vnguyen46
Contributor

Hi,
After migrated Splunk Enterprise to a new hardware, my HFs stop receiving logs over port 514/1514. It's verified these ports are open on the new HFs. The new system is receiving logs from UFs running on Windows and from Cloud-based (AWS).

What other configuration needs to be done like syslog daemon or any things else for the new HFs to receive logs being sent over port 514/1514 like F5 and other network devices?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the ports have a listener on them. Check your firewall(s) to ensure connectivity.
If the HF moved to a new address, make sure all clients have that address.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Don't you think I need to configure the daemon syslog on the new HFs so they can receive the logs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you absolutely need to do that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Hi Richgalloway,

I'd like to circle back on HFs stopped receiving logs. All logs were once received well after system admin fixed the daemon log. Then last Thursday, HFs suddenly stopped receiving 9 out of 10 logs at almost same time. There is no issue with new logs. Disk space and network connection are not the cause.

Would you please share what you think?

Thank you,

0 Karma

vnguyen46
Contributor

"Verify the ports have a listener on them" - would you please give more details on this?

Thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use netstat -ln | grep 514.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

I used nc and received this:
ss -lnt4p | grep 514
LISTEN 0 128 :514 *:
LISTEN 0 128 127.0.0.1:51490 :
LISTEN 0 128 :1514 *:

Does that mean I have listeners on both 514 and 1514?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...