<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk not receiving data from forwarders in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601549#M12842</link>
    <description>&lt;P&gt;Something has changed here:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Invalid key in stanza [WinHostMon://Host OperatingSystem] in C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\inputs.conf, line 172: showZeroValue (value: 1).&lt;/LI-CODE&gt;&lt;P&gt;Based on naming of this TA, you should as from your local Accenture staff if they can see what was wrong in this installation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2022 13:34:19 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-06-13T13:34:19Z</dc:date>
    <item>
      <title>Why is Splunk not receiving data from forwarders?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601456#M12831</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Splunk not receiving data from forwarders. Host os Windows Server 2012 R2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;1. Restart Splunk forwarder not working, getting some error message on CMD prompt.&lt;/P&gt;
&lt;P&gt;2. Re-install Splunk forwarder, data start indexing for a few minutes and stopped again&lt;/P&gt;
&lt;P&gt;3. Checked Splunk forwarder service, all the time it is running state&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Getting below error(smaple part of the error) when restart forwarder:&lt;/P&gt;
&lt;P&gt;No spec file for: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_hostservice360-windows_adc_win-x86-64_iis\local\app.conf&lt;BR /&gt;Checking: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_hostservice360-windows_adc_win-x86-64_iis\local\inputs.conf&lt;BR /&gt;Checking: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_hostservice360-windows_adc_win-x86-64_iis\local\props.conf&lt;BR /&gt;No spec file for: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\app.conf&lt;BR /&gt;Checking: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\inputs.conf&lt;BR /&gt;Invalid key in stanza [WinHostMon://Host OperatingSystem] in C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\inputs.conf, line 172: showZeroValue (value: 1).&lt;BR /&gt;Did you mean 'source'?&lt;BR /&gt;Did you mean 'source type'?&lt;BR /&gt;Invalid key in stanza [WinHostMon://Host Processor] in C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\inputs.conf, line 179: showZeroValue (value: 1).&lt;BR /&gt;Did you mean 'source'?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 19:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601456#M12831</guid>
      <dc:creator>ankurborah</dc:creator>
      <dc:date>2022-06-13T19:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601462#M12832</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It seems that you have quite old Windows version. Have you check that your UF version is supported on that OS level?&lt;/P&gt;&lt;P&gt;Error messages said that you have some unknown options in inputs.conf. Have you check that your TA is supported on your UF version?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 05:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601462#M12832</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-13T05:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601463#M12833</link>
      <description>&lt;P&gt;It was working till yesterday. Also, we are&amp;nbsp; monitoring similar types of os for other hosts.&amp;nbsp; There is no upgrade or downgrade of the issue hosts in the last 2 months.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 05:27:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601463#M12833</guid>
      <dc:creator>ankurborah</dc:creator>
      <dc:date>2022-06-13T05:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601465#M12834</link>
      <description>&lt;P&gt;Was there any OS updates/patching or was node or UF service restarted? If so, then the change which has broken it can be done a long time ago and now it has affected after restart. Almost every time there have been some changes if things goes broken. No you just need to find what that change was.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 05:30:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601465#M12834</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-13T05:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601483#M12838</link>
      <description>&lt;P&gt;Windows patch updates happened every month on 26th on all hosts(400+).&amp;nbsp; Only this host stopped reporting on 1 Jun 2022. Then tried with restart 5th Jun.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 07:26:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601483#M12838</guid>
      <dc:creator>ankurborah</dc:creator>
      <dc:date>2022-06-13T07:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601549#M12842</link>
      <description>&lt;P&gt;Something has changed here:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Invalid key in stanza [WinHostMon://Host OperatingSystem] in C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk-TA-acn_infra360host_adc_win-x86-64\local\inputs.conf, line 172: showZeroValue (value: 1).&lt;/LI-CODE&gt;&lt;P&gt;Based on naming of this TA, you should as from your local Accenture staff if they can see what was wrong in this installation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 13:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601549#M12842</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-13T13:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601573#M12843</link>
      <description>&lt;P&gt;If you reinstall the forwarder and everything seems to be working fine, then it stops, it suggests that the initial state of the forwarder after installation is ok and then it's being "misconfigured" by an app deployed from the deployment server which contains erroneous settings within the deployed app.&lt;/P&gt;&lt;P&gt;Do other forwarder contained within the same serverclass behave the same way?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 14:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-not-receiving-data-from-forwarders/m-p/601573#M12843</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-13T14:27:07Z</dc:date>
    </item>
  </channel>
</rss>

