<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I not getting logs from one source? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636785#M15898</link>
    <description>&lt;P&gt;i checked&amp;nbsp; disabled is 0&lt;BR /&gt;&lt;SPAN&gt;Use the&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;splunk list monitor&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;command --&amp;gt; for this i dont have access to universal&amp;nbsp;forwarder to check&amp;nbsp;&lt;BR /&gt;i mentioned the source which was not coming in the search&amp;nbsp; with index=_internal source=splunkd&amp;nbsp; but i don't see any logs.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 22:49:16 GMT</pubDate>
    <dc:creator>Ash1</dc:creator>
    <dc:date>2023-03-30T22:49:16Z</dc:date>
    <item>
      <title>Why am I not getting logs from one source?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636763#M15894</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have 2 servers&amp;nbsp; and each having 3 sources.&lt;/P&gt;
&lt;P&gt;I am able to receive logs from 2 sources&amp;nbsp; from 2 servers but not receiving logs from one source&lt;/P&gt;
&lt;P&gt;I checked there are logs on the server and no permission issues&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to troubleshoot???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 18:51:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636763#M15894</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2023-03-30T18:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting logs from one source?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636767#M15895</link>
      <description>&lt;P&gt;Verify the inputs are not disabled.&lt;/P&gt;&lt;P&gt;Use the &lt;FONT face="courier new,courier"&gt;splunk list monitor&lt;/FONT&gt; command to make sure the expected files are being monitored.&lt;/P&gt;&lt;P&gt;Check splunkd.log for messages relating to the files.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 19:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636767#M15895</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-30T19:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting logs from one source?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636785#M15898</link>
      <description>&lt;P&gt;i checked&amp;nbsp; disabled is 0&lt;BR /&gt;&lt;SPAN&gt;Use the&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;splunk list monitor&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;command --&amp;gt; for this i dont have access to universal&amp;nbsp;forwarder to check&amp;nbsp;&lt;BR /&gt;i mentioned the source which was not coming in the search&amp;nbsp; with index=_internal source=splunkd&amp;nbsp; but i don't see any logs.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 22:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636785#M15898</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2023-03-30T22:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting logs from one source?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636855#M15905</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is one old answer (you could found lot of those)&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-data-when/m-p/202949" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-data-when/m-p/202949&lt;/A&gt;&amp;nbsp;to solve this kind of issues.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 10:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/636855#M15905</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-03-31T10:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting logs from one source?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/639690#M16006</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, thank you for your inputs.&lt;BR /&gt;Actually the source was not added in inputs, i noticed it lately and added it, now i can see the logs.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 21:10:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-not-getting-logs-from-one-source/m-p/639690#M16006</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2023-04-12T21:10:07Z</dc:date>
    </item>
  </channel>
</rss>

