<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for Nextcloud no data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508734#M62452</link>
    <description>&lt;P&gt;Hello! Tell me, how can I solve the problem for these errors?&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 06:16:47 GMT</pubDate>
    <dc:creator>alex_nemtsev</dc:creator>
    <dc:date>2020-07-13T06:16:47Z</dc:date>
    <item>
      <title>Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/507998#M62394</link>
      <description>&lt;P&gt;Hi! please help us solve the problem of missing data from the Nextcloud server. Splunk was installed and configured according to the instructions. But there is no data in the web interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-3.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9558i0F98C9D352826D12/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Splunk-3.PNG" alt="Splunk-3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9559i11C6E40B7CD12F52/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Splunk-1.PNG" alt="Splunk-1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9560iBF67FBF9A6075BF8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Splunk-2.PNG" alt="Splunk-2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 07:37:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/507998#M62394</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-08T07:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508077#M62405</link>
      <description>What messages do you see when you click on "TailReader-0" in the Health Status screen?&lt;BR /&gt;Have you checked the indexer queues in the Monitoring Console?</description>
      <pubDate>Wed, 08 Jul 2020 13:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508077#M62405</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-08T13:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508284#M62426</link>
      <description>&lt;P&gt;Thanks for the answer! Tell me how to check the status of indexer queues? Warning message " TailReader-0":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-4.PNG" style="width: 856px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9581iA50FD12ABADDD303/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-4.PNG" alt="Splunk-4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-5.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9582i77EDCBF5E3B61C91/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-5.PNG" alt="Splunk-5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 12:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508284#M62426</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-09T12:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508734#M62452</link>
      <description>&lt;P&gt;Hello! Tell me, how can I solve the problem for these errors?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 06:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/508734#M62452</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-13T06:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509018#M62461</link>
      <description>&lt;P&gt;Hello! Can someone help me solve my problem?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 09:12:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509018#M62461</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-14T09:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509068#M62463</link>
      <description>&lt;P&gt;Try increasing the value of &lt;FONT face="courier new,courier"&gt;maxKBps&lt;/FONT&gt;&amp;nbsp;in limits.conf and restarting the forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 12:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509068#M62463</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-14T12:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509676#M62518</link>
      <description>&lt;P&gt;Hello! Thanks for the answer! I set the parameter maxKBps = 4096, but the data is not displayed.&amp;nbsp; Are there any other versions of how you can solve the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="maxkbs.PNG" style="width: 242px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9738i49BF0B92239EF40B/image-size/large?v=v2&amp;amp;px=999" role="button" title="maxkbs.PNG" alt="maxkbs.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-6.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9739iB2FF90A0D3D24D1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-6.PNG" alt="Splunk-6.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 10:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509676#M62518</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-17T10:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509686#M62520</link>
      <description>&lt;P&gt;Tell us more about your Splunk environment.&amp;nbsp; What is the ingestion rate?&amp;nbsp; How many indexers?&amp;nbsp; Are they clustered (it looks like they are not)?&amp;nbsp; How many searches are you running?&lt;/P&gt;&lt;P&gt;Please sign in to an indexer and check the Monitoring Console there.&amp;nbsp; Also, check splunkd.log for errors.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 12:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509686#M62520</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-17T12:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509705#M62523</link>
      <description>&lt;P&gt;Unfortunately I will not be able to answer all your questions. Splunk is installed on the Nextcloud server according to the instructions, except for this, nothing else has been configured by splunk. When I started splunkforwarder, I got an error that port 8089 is busy and I changed it to 9089. Here is the data from the Monitoring Console and splunk.log. I hope I understood you correctly and sent the necessary data.&lt;/P&gt;&lt;P&gt;&lt;A href="https://intranet.graabek.com/cloud/index.php/s/Lc9oXkaWNmQHBqG#pdfviewer" target="_blank"&gt;https://intranet.graabek.com/cloud/index.php/s/Lc9oXkaWNmQHBqG#pdfviewer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;07-17-2020 16:08:35.807 +0300 INFO TcpOutputProc - Removing quarantine from idx=127.0.0.1:9997&lt;BR /&gt;07-17-2020 16:08:35.807 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused&lt;BR /&gt;07-17-2020 16:08:35.807 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed&lt;BR /&gt;07-17-2020 16:08:35.807 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused&lt;BR /&gt;07-17-2020 16:08:35.807 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed&lt;BR /&gt;07-17-2020 16:08:35.807 +0300 WARN TcpOutputProc - Applying quarantine to ip=127.0.0.1 port=9997 _numberOfFailures=2&lt;BR /&gt;07-17-2020 16:09:55.913 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;07-17-2020 16:11:35.926 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10700. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;07-17-2020 16:13:15.942 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10800. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;07-17-2020 16:14:04.615 +0300 INFO TcpOutputProc - Removing quarantine from idx=127.0.0.1:9997&lt;BR /&gt;07-17-2020 16:14:04.616 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused&lt;BR /&gt;07-17-2020 16:14:04.616 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed&lt;BR /&gt;07-17-2020 16:14:04.616 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused&lt;BR /&gt;07-17-2020 16:14:04.616 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed&lt;BR /&gt;07-17-2020 16:14:04.616 +0300 WARN TcpOutputProc - Applying quarantine to ip=127.0.0.1 port=9997 _numberOfFailures=2&lt;BR /&gt;(END)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-indexi-1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9747iDB11E51159070707/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-indexi-1.PNG" alt="Splunk-indexi-1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-indexi-2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9748iC9F02032D44FE913/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-indexi-2.PNG" alt="Splunk-indexi-2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-indexi-3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9745iF27B29A555F3F9EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-indexi-3.PNG" alt="Splunk-indexi-3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-indexi-4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9746i280CE2945D67D487/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-indexi-4.PNG" alt="Splunk-indexi-4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 13:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509705#M62523</guid>
      <dc:creator>alex_nemtsev</dc:creator>
      <dc:date>2020-07-17T13:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Nextcloud no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509711#M62524</link>
      <description>&lt;P&gt;How did you miss these messages?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;07-17-2020 16:08:35.807 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused
07-17-2020 16:08:35.807 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed&lt;/LI-CODE&gt;&lt;P&gt;This would seem to be the root cause of the problem.&amp;nbsp; Is 9997 the correct port for your indexer?&amp;nbsp; Have you checked your firewalls to verify traffic is allowed to port 9997?&lt;/P&gt;&lt;P&gt;Are you running a forwarder on the same server as another Splunk instance?&amp;nbsp; Don't do that.&amp;nbsp; Splunk can monitor files on the local system without help from a forwarder.&amp;nbsp; This would explain why port 8089 is already in use.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 13:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Nextcloud-no-data/m-p/509711#M62524</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-17T13:48:28Z</dc:date>
    </item>
  </channel>
</rss>

