<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk isn't logging any of my data in a new 8.0.2 install in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469819#M1782</link>
    <description>&lt;P&gt;Hi Chris,&lt;/P&gt;

&lt;P&gt;if I understand all correctly you have a syslog server (kiwi) and a splunk server and you sending syslog data to the splunk server using UDP/TCP to the default port 514.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;have you enabled and configured a syslog input port on the splunk server? It should accept the same protocol (TCP/UDP) and be on the same port (514). It is NOT a splunk receiver port.&lt;/LI&gt;
&lt;LI&gt;the procedure is different if you're using splunk universal forwarder instead of syslog&lt;/LI&gt;
&lt;LI&gt;can you check that the date is coming in using Wireshark?&lt;/LI&gt;
&lt;LI&gt;can you check both Kiwi Log and $SPLUNK_HOME/var/log/splunk/splunkd.log ?&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 08 Apr 2020 08:14:30 GMT</pubDate>
    <dc:creator>PavelP</dc:creator>
    <dc:date>2020-04-08T08:14:30Z</dc:date>
    <item>
      <title>Splunk isn't logging any of my data in a new 8.0.2 install</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469818#M1781</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I'm a very novice Spluker and have only really upgraded it once and installed it a couple times on our servers to update it. Right now I just installed a new Splunk instance on Server 2019 and am about to migrate our existing Splunk 2012 server over to it. I have already migrated just the warm buckets over to the new server in the cold location. I can search that data, and that's good.&lt;/P&gt;
&lt;P&gt;The problem is that I'm sending test data over to the new Splunk 8.0.2 server and it's either not getting it or not indexing it. I followed Splunk 8.0.2's Can't Find My Data Doc &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Troubleshooting/Cantfinddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Troubleshooting/Cantfinddata&lt;/A&gt; and the Splunk instance is only one server, no forwarders, no separate servers, just everything in one server.&lt;/P&gt;
&lt;P&gt;Troubleshooting I have done:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Everything I could understand and that&lt;BR /&gt;is applicable in Splunk 8.0.2's Can't Find My Data Doc&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Troubleshooting/Cantfinddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I confirmed the Splunk service is&lt;BR /&gt;running on the server.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I can ping the server from the network&lt;BR /&gt;device, and I can ping the network&lt;BR /&gt;device from the server. There are no&lt;BR /&gt;Firewalls in place between the device and server and the Windows&lt;BR /&gt;Server 2019 FW is turned off.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I checked the Windows File structure&lt;BR /&gt;in the actual VM and it hasn't created&lt;BR /&gt;a hot bucket yet, so if it's getting&lt;BR /&gt;the data, it's not&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I also installed a Kiwi Syslog server&lt;BR /&gt;on my desktop and put my IP in the&lt;BR /&gt;network device and sure enough it's&lt;BR /&gt;sending data.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I'm not really sure what else to try, so any help or things to check would be appreciated.&lt;/P&gt;
&lt;P&gt;Thanks Splunk Answers!&lt;/P&gt;
&lt;P&gt;-Chris&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 21:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469818#M1781</guid>
      <dc:creator>christopherryan</dc:creator>
      <dc:date>2020-06-08T21:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk isn't logging any of my data in a new 8.0.2 install</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469819#M1782</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;

&lt;P&gt;if I understand all correctly you have a syslog server (kiwi) and a splunk server and you sending syslog data to the splunk server using UDP/TCP to the default port 514.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;have you enabled and configured a syslog input port on the splunk server? It should accept the same protocol (TCP/UDP) and be on the same port (514). It is NOT a splunk receiver port.&lt;/LI&gt;
&lt;LI&gt;the procedure is different if you're using splunk universal forwarder instead of syslog&lt;/LI&gt;
&lt;LI&gt;can you check that the date is coming in using Wireshark?&lt;/LI&gt;
&lt;LI&gt;can you check both Kiwi Log and $SPLUNK_HOME/var/log/splunk/splunkd.log ?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 08 Apr 2020 08:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469819#M1782</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-08T08:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk isn't logging any of my data in a new 8.0.2 install</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469820#M1783</link>
      <description>&lt;P&gt;Thank you, Thank you, Thank you PavelP!!!&lt;/P&gt;

&lt;P&gt;I did a total facepalm once I realized Splunk didn't listen on any port by default. Once I added that information I instantly started getting the logs I was expecting. &lt;/P&gt;

&lt;P&gt;Thank you for kindly pointing me in the right direction &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 14:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-isn-t-logging-any-of-my-data-in-a-new-8-0-2-install/m-p/469820#M1783</guid>
      <dc:creator>christopherryan</dc:creator>
      <dc:date>2020-04-08T14:51:45Z</dc:date>
    </item>
  </channel>
</rss>

