we're in the process of investigating why our heavy forwarders are not forwarding events from the myriad universal forwarders to our indexer.
in the diagnostic process we ran ./splunk display app from one of our heavy forwarders. the results show:
SplunkForwarder UNCONFIGURED ENABLED.
can anyone explain what issue we might have that causes the status to show UNCONFIGURED, yet enabled.
we're missing something......
thanks in advance.
michaelS
ANSWERED, but still curious.
although the output of the list forward-server showed all active forwards correctly, we re-issued the add forward-server command and now the events are correctly being forwarded.
there must be something subtle that requires that the add forward server command be run even though all forward servers are already configured.....
if anyone can comment on this...we'd appreciated it..
anyway, we're up now....thanks all.
ANSWERED, but still curious.
although the output of the list forward-server showed all active forwards correctly, we re-issued the add forward-server command and now the events are correctly being forwarded.
there must be something subtle that requires that the add forward server command be run even though all forward servers are already configured.....
if anyone can comment on this...we'd appreciated it..
anyway, we're up now....thanks all.
Splunk heavy forwarders had been working....recent upgrade of OS (Linux) and re-create of forwarder results in heavy forwarders NOT relaying events from lower tier universal forwarders
we're just missing something on re-create effort
from universal forwarders, list forward-server shows the heavy forwarder and indexer OK.
Thanks much....version 4.2.5