Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why _internal logs from heavy forwarder is not getting to indexers after a splunkd restart but _audit are?

$
0
0
All of a sudden _internal logs from HF stopped coming to indexers after a splunkd restart. But i see _audit logs making it to indexers. I see splunkd.log on HF is growing. There is no change in inputs.conf or outputs.conf before restart. What could be the reason?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>