<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk instance not receiving data issue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-instance-not-receiving-data-issue/m-p/568817#M10120</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209306"&gt;@pacifikn&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;To start with can you check in splunkd.log (/&lt;SPAN&gt;opt/splunkforwarder/var/log/splunk/splunkd.log) and see what is happening when you start service? there may be several reasons for it's&amp;nbsp; failure also check if you have any filesystem full etc.,&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 18:14:07 GMT</pubDate>
    <dc:creator>sanjeev543</dc:creator>
    <dc:date>2021-09-28T18:14:07Z</dc:date>
    <item>
      <title>splunk instance not receiving data issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-instance-not-receiving-data-issue/m-p/568474#M10088</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;hope you are doing well.&lt;/P&gt;&lt;P&gt;I really need your support to the issue ,I have experienced about logs not received from syslog sender devices&amp;nbsp;&lt;/P&gt;&lt;P&gt;into Splunk instance. before logs were received, but today no logs are coming,&amp;nbsp;&lt;/P&gt;&lt;P&gt;#I have checked splunk forwarders i found is running&lt;/P&gt;&lt;P&gt;also checked splunkd it is also running,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But also I found error but ii don't know if this is the root cause that cause this matter,&lt;/P&gt;&lt;P&gt;Below is the issue I found when I check the status, AND even when I do&amp;nbsp;systemctl restart splunk-suf.service this doesn't work, still it gives me failed status!&lt;/P&gt;&lt;P&gt;bash-4.2$ systemctl status splunk-suf.service&lt;BR /&gt;* splunk-suf.service - splunk Universal Forwarder service&lt;BR /&gt;Loaded: loaded (/etc/systemd/system/splunk-suf.service; enabled; vendor preset:disabled)&lt;BR /&gt;Active: failed (Result: start-limit) since Sat 2021-09-25 11:28:14 CAT; 3min 3s ago&lt;BR /&gt;Process: 58723 ExecStart=/opt/splunkforwarder/bin/splunk _internal_launch_under_systemd --accept-license --no-prompt --answer-yes (code=exited, status=1, FAILURE)&lt;BR /&gt;Main PID: 58723 (code=exited, status=1/FAILURE)&lt;/P&gt;&lt;P&gt;***Kindly help me on how I may solve this issue and share with me the troubleshooting CLI commands to check why receiver Splunk instance are not receiving logs?&lt;/P&gt;&lt;P&gt;** I want to check also if the firewall is not blocking anything, what different command to use?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or any other advice that may help me to resolve this?&lt;/P&gt;&lt;P&gt;**MY OS: Centos, Splunk enterprise&lt;/P&gt;&lt;P&gt;Kindly help me on this matter, and share with me other command I can use to troubleshooting this and how i can fix this?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Sep 2021 19:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-instance-not-receiving-data-issue/m-p/568474#M10088</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2021-09-25T19:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunk instance not receiving data issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-instance-not-receiving-data-issue/m-p/568817#M10120</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209306"&gt;@pacifikn&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;To start with can you check in splunkd.log (/&lt;SPAN&gt;opt/splunkforwarder/var/log/splunk/splunkd.log) and see what is happening when you start service? there may be several reasons for it's&amp;nbsp; failure also check if you have any filesystem full etc.,&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 18:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-instance-not-receiving-data-issue/m-p/568817#M10120</guid>
      <dc:creator>sanjeev543</dc:creator>
      <dc:date>2021-09-28T18:14:07Z</dc:date>
    </item>
  </channel>
</rss>

