<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot fetch data into Splunk for Nagios in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52434#M70218</link>
    <description>&lt;P&gt;Just by looking at what you have there it doesn't look like you have the sourcetypes right.  Also, do you have them going into the nagios index?&lt;/P&gt;

&lt;P&gt;Sourcetypes should be:&lt;BR /&gt;
nagios&lt;BR /&gt;
nagiosserviceperf&lt;BR /&gt;
nagioshostperf&lt;/P&gt;</description>
    <pubDate>Fri, 07 Sep 2012 04:33:56 GMT</pubDate>
    <dc:creator>jgedeon120</dc:creator>
    <dc:date>2012-09-07T04:33:56Z</dc:date>
    <item>
      <title>Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52431#M70215</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;

&lt;P&gt;I have recently installed Splunk for Nagios and followed the configuration guidelines shown here:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/22374/splunk-for-nagios"&gt;http://splunk-base.splunk.com/apps/22374/splunk-for-nagios&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If I go to Search app, I can see the Nagios log file and its events, but nothing shows on Splunk for Nagios dashboards.&lt;/P&gt;

&lt;P&gt;What may be the cause? I will provide the configuration files contents as you ask me.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;/P&gt;

&lt;P&gt;Bruno Martins&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2012 09:49:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52431#M70215</guid>
      <dc:creator>bmomartins</dc:creator>
      <dc:date>2012-09-06T09:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52432#M70216</link>
      <description>&lt;P&gt;all of the dashboards use searches based on index = nagios then you either modify all the searches or you get the data into an index which you created/named nagios.&lt;/P&gt;

&lt;P&gt;And you need to make sure you have the right sourcetype assigned to the right data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$NAGIOS_HOME/var/nagios.log sourcetype=nagios

$NAGIOS_HOME/var/host-perfdata sourcetype=nagioshostperf

$NAGIOS_HOME/var/service-perfdata sourcetype=nagiosserviceperf
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Sep 2012 10:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52432#M70216</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-09-06T10:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52433#M70217</link>
      <description>&lt;P&gt;Thanks for the fast response.&lt;/P&gt;

&lt;P&gt;I have three sourcetypes:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;serviceperf = /tmp/service-perfdata.log
hostperf = /tmp/host-perfdata.log
nagios = /var/log/nagios/nagios.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the Search app I see the files being indexed, but no information displayed in app Splunk for Nagios.&lt;/P&gt;

&lt;P&gt;I have a index called nagios, but I can see that those files are being used by main index. How can I change this?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2012 11:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52433#M70217</guid>
      <dc:creator>bmomartins</dc:creator>
      <dc:date>2012-09-06T11:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52434#M70218</link>
      <description>&lt;P&gt;Just by looking at what you have there it doesn't look like you have the sourcetypes right.  Also, do you have them going into the nagios index?&lt;/P&gt;

&lt;P&gt;Sourcetypes should be:&lt;BR /&gt;
nagios&lt;BR /&gt;
nagiosserviceperf&lt;BR /&gt;
nagioshostperf&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2012 04:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52434#M70218</guid>
      <dc:creator>jgedeon120</dc:creator>
      <dc:date>2012-09-07T04:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52435#M70219</link>
      <description>&lt;P&gt;for the existing you cannot but new data you need to modify in your forwarders the inputs.conf by adding the following new line for each sourcetypes:&lt;/P&gt;

&lt;P&gt;index=nagios&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2012 06:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52435#M70219</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-09-07T06:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52436#M70220</link>
      <description>&lt;P&gt;Ok, after some changes I have this working with one exception.&lt;/P&gt;

&lt;P&gt;In the Livestatus Dashboard I should see service status the same way I can see that all hosts are up. Got to figure out why it is not getting information, because the log file from which it extracts this information is populated with events.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2012 09:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52436#M70220</guid>
      <dc:creator>bmomartins</dc:creator>
      <dc:date>2012-09-07T09:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot fetch data into Splunk for Nagios</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52437#M70221</link>
      <description>&lt;P&gt;Hi Bruno,&lt;/P&gt;

&lt;P&gt;Please upgrade to the latest release and let me know how you go &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;All the best,&lt;/P&gt;

&lt;P&gt;Luke &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2013 07:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-fetch-data-into-Splunk-for-Nagios/m-p/52437#M70221</guid>
      <dc:creator>lukeh</dc:creator>
      <dc:date>2013-10-04T07:32:45Z</dc:date>
    </item>
  </channel>
</rss>

