Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Splunk Universal Forwarder is not able to send monitored file's logs to Splunk Indexers though sending internal logs properly

$
0
0
Hi All, I have six forwarders and two indexers to which these are supposed to send data. The six forwarders have multiple instances of forwarders i.e., each having three instances. There are three active files of 500mb each which are supposed to be monitored. These three 500mb files are distributed among three instances of forwarders in each forwarder. After setting up the forwarders and doing all the configurations, I started the input for all the six forwarders. Out of six forwarders, 4 are sending data properly but 2 are monitoring the files and not sending any data. Internal logs are coming from all six forwarders. There is no internal error that I'm getting. Also at the time of data input, I was able to get the "TailingProcessor" in the internal logs for the sources. But after that the logs never came. I'm not able to find what the issue could be. Can anybody please help me to solve this issue?

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>