Hi Team,
We have an log file in one of the server and which is keep generated in the directory for every 10 mins once as below,
12/13/17 10:10 log1213171010
12/13/17 10:20 log1213171020
12/13/17 10:30 log1213171030
12/13/17 10:40 log1213171040
...........
...........
12/13/17 11:50 log1213171150 and keeps going.
We had an issue, our Splunk indexer was down for some 2 hours and we have fixed the splunk indexer issue. But we have noticed that, the above logs are not in Splunk for that particular span of time when the indexer was down. But the same time forwarder was up & running fine.
I have few question on this.
1. When the universal forwarder is not able to connect to respective indexer(standalone), will the forwarder still be collecting data from the server?
2. If forwarder is collecting the data, then will it resend the old data once the connection established with indexer.
Please help me on this.
↧