<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126462#M10007</link>
    <description>&lt;P&gt;I am suspecting problem with your inputs.conf &lt;CODE&gt;[monitor:///var/log]&lt;/CODE&gt;&lt;BR /&gt;
Shouldn't it be &lt;CODE&gt;[monitor:///var/log/*]&lt;/CODE&gt; ? &lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2015 07:22:44 GMT</pubDate>
    <dc:creator>satishsdange</dc:creator>
    <dc:date>2015-07-17T07:22:44Z</dc:date>
    <item>
      <title>Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126458#M10003</link>
      <description>&lt;P&gt;I have Splunk Light v6.2.3 instance with the Add-on for &lt;EM&gt;Nix V5.1.2 running.  I have two universal forwarders v6.2.1 identically configured on two different Red Hat servers running the same operating system.  I want to send all the logs from `/var/log/&lt;/EM&gt;` to splunk.  One server works and one server doesn't.  I have verified connectivity from both servers.  The one that doesn't work is slated to be the production instance of the one that works.  &lt;/P&gt;

&lt;P&gt;etc/system/local/inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = host1
index = syslog
disabled = false
[monitor:///var/log]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;etc/system/local/outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = linux-group
disabled = 0
[tcpout:linux-group]
server = ##.##.##.32:514
[tcpout-server://##.##.##.32:514]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Pretty basic config.  I have a Windows forwarder which also works fine.&lt;/P&gt;

&lt;P&gt;I think I've read every Splunk doc there is and run every diagnostic I could.  I've seen posts of others with a similar issue here and have verified every one of those answers marked as correct.  There are some mention of associating the host with an index, but the steps only apply to the enterprise version.  I can see data coming from both hosts in the receiver logs, it just doesn't show up in the interface.  I've tried using different ports, reinstalling, and tried various versions just in case.   Any help would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 16:14:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126458#M10003</guid>
      <dc:creator>rlorenzon</dc:creator>
      <dc:date>2015-07-16T16:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126459#M10004</link>
      <description>&lt;P&gt;Also, the hostnames are different as well as their GUID's in etc/instance.cfg   - They were clean installations.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 16:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126459#M10004</guid>
      <dc:creator>rlorenzon</dc:creator>
      <dc:date>2015-07-16T16:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126460#M10005</link>
      <description>&lt;P&gt;Also, just noticed this message in the splunk interface with the hostname of the one that I can't see: &lt;/P&gt;

&lt;P&gt;received event for unconfigured/disabled/deleted index='syslog' with source='source::/var/log/dmesg.old' host='host::infoleaf' sourcetype='sourcetype::backup_file' (1 missing total)&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 17:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126460#M10005</guid>
      <dc:creator>rlorenzon</dc:creator>
      <dc:date>2015-07-16T17:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126461#M10006</link>
      <description>&lt;P&gt;So it sounds like your syslog index is all begarbled - is there anyway you can delete the syslog index and create a new one ? That is just what I would do, not necessarily a solution &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 17:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126461#M10006</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2015-07-16T17:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126462#M10007</link>
      <description>&lt;P&gt;I am suspecting problem with your inputs.conf &lt;CODE&gt;[monitor:///var/log]&lt;/CODE&gt;&lt;BR /&gt;
Shouldn't it be &lt;CODE&gt;[monitor:///var/log/*]&lt;/CODE&gt; ? &lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 07:22:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126462#M10007</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-07-17T07:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126463#M10008</link>
      <description>&lt;P&gt;Followed this great step by step document again:.&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/50082/how-do-i-configure-a-splunk-forwarder-on-linux.html"&gt;http://answers.splunk.com/answers/50082/how-do-i-configure-a-splunk-forwarder-on-linux.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Was failing on step 7 as others have had.  I manually created the directory:&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/search/local &lt;/P&gt;

&lt;P&gt;and the inputs.conf file in it with:&lt;BR /&gt;
[monitor:///var/log]&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;and it worked!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 17:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126463#M10008</guid>
      <dc:creator>rlorenzon</dc:creator>
      <dc:date>2015-07-17T17:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126464#M10009</link>
      <description>&lt;P&gt;If you look at the example &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf?utm_source=answers&amp;amp;utm_medium=incontext&amp;amp;utm_term=inputs.conf&amp;amp;utm_campaign=refdoc#inputs.conf.example"&gt;here&lt;/A&gt;, it should be valid without the &lt;CODE&gt;*&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 18:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126464#M10009</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2015-07-17T18:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why is one Linux universal forwarder host and data not showing up in Splunk Light?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126465#M10010</link>
      <description>&lt;P&gt;@rlorenzon glad to hear you figured it out. Go ahead and accept your own answer to close the question. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 18:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-one-Linux-universal-forwarder-host-and-data-not-showing/m-p/126465#M10010</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2015-07-17T18:55:09Z</dc:date>
    </item>
  </channel>
</rss>

