Splunk Enterprise

Forwarder cert expired, lost data ingestion during this time period

sbrice18
Path Finder

Splunk Forwarder V 6.5.2- Our certs expired at midnight and we renewed them at 10 am. Log ingestion picked back up at 10 am but everything prior is missing. This log file did not role over, shouldn't the forwarder know that there is a chunk of missing data from 12am to 10:00am? Do I need to re-ingest this log file or clean the fishbucket on the forwarder? Seems like this might be a bug? We also have indexer ack=true enabled.

Tags (1)
0 Karma

somesoni2
Revered Legend

Splunk should pickup those old values. Cleaning fishbucket would cause the whole file to be read again, along with all other data monitoring that was happening. Try restarting Splunk on the forwarder. Also, how much data is there on file? If it's a huge file, you can expect some delay till Splunk catches up.

0 Karma

sbrice18
Path Finder

Thanks for the reply! After pushing the new cert I restarted the forwarder and everything connected fine. The log file is only 48MB in size. We validated the crc and it looks like the forwarder tracked everything from file creation . Its been a few hours now but splunk still only shows data from 10am onward. I was going to do a one-shot but I don't want to duplicate the events from 10 am 🙂 I was thinking maybe the forwarder buffer ran over but at 30MB it should have retained the data without any issues. Its like the forwarder thinks it sent the data to the indexers. -odd (6.5.2 fwd /v 7.0.1 on indexers)

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...