Getting Data In

Splunk Forwarder Service continually stops

gobofo
New Member

We have 2 Windows Servers (2008 and 2003), the Universal Splunk forwarder continually stops, every few hours.

  1. Where should I be looking to see what the cause is.

  2. Any known fixes or issues?

Thanks

0 Karma

japrivacy
New Member

checking in the windows event application event logs, the splunk modular powershell.exe would die.

common logging error

but also my server has a local.meta path issue.

0 Karma

mzorzi
Splunk Employee
Splunk Employee

If that happens periodically I would check the Windows Event Logs

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

What version of the UF? Are there any messages in $SPLUNK_HOME/var/log/splunk/splunkd.log around the time of the failure? What about in the windows event logs?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...