The forwarder samples its metrics and sends them to Wirespeed in batches, so recent activity can take a few minutes to appear.
Summary cards
HTTP error responses are not counted in Events Refused or Errors. They appear in the HTTP Status chart.
No data or inactivity banner
If the forwarder has not received any data in a while, a banner appears at the top of the tab. A source that has gone quiet looks the same as a forwarder that is down, so start with the source:- Confirm the source is on and configured to send logs
- Compare the destination address, port, and protocol on the source with Forwarder Details
- Check that the source’s TLS setting matches TLS: Enabled or TLS: Disabled in Forwarder Details. For TLS, see Syslog over TLS
- Confirm your firewalls allow traffic from the source to the forwarder
Errors
This chart shows events and connections the forwarder could not accept, one series per cause. An empty chart is healthy.Forwarders are reachable from the internet, so automated scanners sometimes connect to them. This can show up as Rejected, TCP frame failed, or TLS handshake failed. These usually appear in short bursts, are harmless, and do not mean anything is wrong with your sender. You can ignore an occasional burst, but investigate if the errors continue over a longer period or your events stop showing up.
HTTP Status
This chart applies to integrations that receive logs over HTTP or HTTPS. It shows the responses the forwarder sent, by status code.- 2xx responses are healthy
- 4xx responses mean the request was refused. Check the sender’s address, credentials, and payload format against the integration’s setup instructions
- 5xx responses are usually temporary. Make sure the sender retries, and contact support if they persist

