<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SplunkForwarder monitoring issue for /opt/log/&amp;lt;file name&amp;gt; in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740861#M21773</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257356"&gt;@Namdev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you confirm which user the Splunk Forwarder is running as? Is it&amp;nbsp;&lt;SPAN&gt;splunkfwd, splunk or something else?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please could you show a screenshot of the permissions on your /opt/log files in question.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you run anything like this against the directory to give splunk access?&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;setfacl -R -m u:splunkfwd:r-x /opt/log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Are there any logs in splunkd.log relating to these files?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 22:36:30 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-03-04T22:36:30Z</dc:date>
    <item>
      <title>SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740810#M21769</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;In my distributed Splunk lab created on VMware client virtual machine, facing the below issues.&amp;nbsp; Distributed environment consists of below components with Splunk free&amp;nbsp; licences&lt;/P&gt;&lt;P&gt;- &lt;SPAN class=""&gt;4&lt;/SPAN&gt; Indexers (part &lt;SPAN class=""&gt;of&lt;/SPAN&gt; an Indexer &lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;- &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt; Manager (&lt;SPAN class=""&gt;for&lt;/SPAN&gt; managing the indexer &lt;SPAN class=""&gt;cluster&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;- &lt;SPAN class=""&gt;2&lt;/SPAN&gt; Universal Forwarders (UFs) sending data&lt;/P&gt;&lt;P&gt;- &lt;SPAN class=""&gt;1&lt;/SPAN&gt; DS/LM/MC (Deployment &lt;SPAN class=""&gt;Server&lt;/SPAN&gt; + License Manager + Monitoring Console combined &lt;SPAN class=""&gt;on&lt;/SPAN&gt; one &lt;SPAN class=""&gt;server&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;- &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;Search&lt;/SPAN&gt; Head (&lt;SPAN class=""&gt;for&lt;/SPAN&gt; searching &lt;SPAN class=""&gt;and&lt;/SPAN&gt; dashboards)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue to enable Splunk monitoring for /opt/log directory.&lt;/P&gt;&lt;P&gt;I have checked that &lt;STRONG&gt;/var/log&lt;/STRONG&gt; can be monitored successfully whereas Splunk forwarder is failed to monitor /opt/log directory. I have checked permission issue other things but no luck&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740810#M21769</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-04T17:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740815#M21770</link>
      <description>&lt;P&gt;I recommend checking the internal logs for the forwarder. It may contain error messages that indicate why /opt/log/ is not logging. You can use various keywords:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;forwardername&amp;gt; log_level=ERROR /opt/log/&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 04 Mar 2025 18:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740815#M21770</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2025-03-04T18:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740861#M21773</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257356"&gt;@Namdev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you confirm which user the Splunk Forwarder is running as? Is it&amp;nbsp;&lt;SPAN&gt;splunkfwd, splunk or something else?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please could you show a screenshot of the permissions on your /opt/log files in question.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you run anything like this against the directory to give splunk access?&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;setfacl -R -m u:splunkfwd:r-x /opt/log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Are there any logs in splunkd.log relating to these files?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 22:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740861#M21773</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T22:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740892#M21778</link>
      <description>&lt;P&gt;Hey Buddy ,&lt;/P&gt;&lt;P&gt;No luck with your command, kindly find logs below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;root@hf2:/opt# ps aux | grep /opt/log/&lt;BR /&gt;root 3152 0.0 0.0 9276 2304 pts/2 S+ 13:17 0:00 grep --color=auto /opt/log/&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;root@hf2:/opt# ls -l /opt/log/&lt;BR /&gt;total 204&lt;BR /&gt;-rw-r-xr--+ 1 root root 207575 Feb 19 11:12 cisco_ironport_web.log&lt;BR /&gt;root@hf2:/opt#&lt;/P&gt;&lt;P&gt;SplunkD Logs for your refernecne :&lt;BR /&gt;03-04-2025 22:23:55.770 +0530 INFO TailingProcessor [32908 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:29:34.873 +0530 INFO TailingProcessor [33197 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:39:22.449 +0530 INFO TailingProcessor [33712 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:44:59.341 +0530 INFO TailingProcessor [33979 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:44:59.341 +0530 INFO TailingProcessor [33979 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:54:52.366 +0530 INFO TailingProcessor [34246 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:54:52.366 +0530 INFO TailingProcessor [34246 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 12:35:53.768 +0530 INFO TailingProcessor [2117 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 12:35:53.768 +0530 INFO TailingProcessor [2117 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 13:07:00.440 +0530 INFO TailingProcessor [2920 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-05-2025 13:16:28.483 +0530 INFO TailingProcessor [3132 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-05-2025 13:18:26.876 +0530 INFO TailingProcessor [3339 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;root@hf2:/opt#&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 07:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740892#M21778</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-05T07:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740907#M21783</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I’m expecting that you have Splunk trial not free license? Free license doesn’t contain most of those features which you are trying to use!&lt;/P&gt;&lt;P&gt;The easiest way to check why those files are not accessible is just sudo/su to your Splunk UF user and check if it can access those or not. If not the add permissions as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;already told. If it can access those, then start to debug with logs and e.g. with&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk list inputstatus &lt;/LI-CODE&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;You could find quite many posts here where this issue is already discussed and solved.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 10:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740907#M21783</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-05T10:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740908#M21784</link>
      <description>&lt;P&gt;NO logs on Search head&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 10:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740908#M21784</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-05T10:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740912#M21785</link>
      <description>&lt;P&gt;I am using Splunk trial license, I have checked permissions and it is not a permission issue&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 11:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740912#M21785</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-05T11:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740921#M21786</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257356"&gt;@Namdev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you get on with looking into the below?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257356"&gt;@Namdev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you confirm which user the Splunk Forwarder is running as? Is it&amp;nbsp;&lt;SPAN&gt;splunkfwd, splunk or something else?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please could you show a screenshot of the permissions on your /opt/log files in question.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you run anything like this against the directory to give splunk access?&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;setfacl -R -m u:splunkfwd:r-x /opt/log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Are there any logs in splunkd.log relating to these files?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 12:30:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740921#M21786</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-05T12:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740929#M21787</link>
      <description>&lt;P&gt;I checked by using this command but no luck , kindly find my logs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;root@hf2:/opt# ps aux | grep /opt/log/&lt;BR /&gt;root 3152 0.0 0.0 9276 2304 pts/2 S+ 13:17 0:00 grep --color=auto /opt/log/&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;root@hf2:/opt# ls -l /opt/log/&lt;BR /&gt;total 204&lt;BR /&gt;-rw-r-xr--+ 1 root root 207575 Feb 19 11:12 cisco_ironport_web.log&lt;BR /&gt;root@hf2:/opt#&lt;/P&gt;&lt;P&gt;SplunkD Logs for your refernecne :&lt;BR /&gt;03-04-2025 22:23:55.770 +0530 INFO TailingProcessor [32908 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:29:34.873 +0530 INFO TailingProcessor [33197 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:39:22.449 +0530 INFO TailingProcessor [33712 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-04-2025 22:44:59.341 +0530 INFO TailingProcessor [33979 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:44:59.341 +0530 INFO TailingProcessor [33979 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:54:52.366 +0530 INFO TailingProcessor [34246 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-04-2025 22:54:52.366 +0530 INFO TailingProcessor [34246 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 12:35:53.768 +0530 INFO TailingProcessor [2117 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 12:35:53.768 +0530 INFO TailingProcessor [2117 MainTailingThread] - Adding watch on path: /opt/log/cisco_ironport_web.log.&lt;BR /&gt;03-05-2025 13:07:00.440 +0530 INFO TailingProcessor [2920 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-05-2025 13:16:28.483 +0530 INFO TailingProcessor [3132 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;03-05-2025 13:18:26.876 +0530 INFO TailingProcessor [3339 MainTailingThread] - Parsing configuration stanza: monitor:///opt/log/.&lt;BR /&gt;root@hf2:/opt#&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 13:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740929#M21787</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-05T13:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740939#M21788</link>
      <description>&lt;P&gt;It good to know that. Then this (on UF)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk list inputstatus&lt;/LI-CODE&gt;&lt;P&gt;Shows to you what inputs your UF sees and what it has read.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 15:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740939#M21788</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-05T15:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740950#M21789</link>
      <description>&lt;P&gt;Cooked:tcp :&lt;BR /&gt;tcp&lt;/P&gt;&lt;P&gt;Raw:tcp :&lt;BR /&gt;tcp&lt;/P&gt;&lt;P&gt;TailingProcessor:FileStatus :&lt;BR /&gt;$SPLUNK_HOME/etc/apps/sample_app/logs&lt;BR /&gt;type = missing&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/etc/splunk.version&lt;BR /&gt;file position = 70&lt;BR /&gt;file size = 70&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk/configuration_change.log&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk/license_usage_summary.log&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk/metrics.log&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/splunk/splunkd.log&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/log/watchdog/watchdog.log*&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/run/splunk/search_telemetry/*search_telemetry.json&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/var/spool/splunk/tracker.log*&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;/opt/log/&lt;BR /&gt;type = directory&lt;/P&gt;&lt;P&gt;/opt/log/cisco_ironport_web.log&lt;BR /&gt;file position = 207575&lt;BR /&gt;file size = 207575&lt;BR /&gt;parent = /opt/log/&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/audit.log&lt;BR /&gt;file position = 159471&lt;BR /&gt;file size = 159471&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = open file&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/btool.log&lt;BR /&gt;file position = 192268&lt;BR /&gt;file size = 192268&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/conf.log&lt;BR /&gt;file position = 9044&lt;BR /&gt;file size = 9044&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/configuration_change.log&lt;BR /&gt;file position = 3353479&lt;BR /&gt;file size = 3353479&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk/configuration_change.log&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/first_install.log&lt;BR /&gt;file position = 70&lt;BR /&gt;file size = 70&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/health.log&lt;BR /&gt;file position = 785728&lt;BR /&gt;file size = 785728&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/license_usage.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/license_usage_summary.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk/license_usage_summary.log&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/mergebuckets.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/metrics.log&lt;BR /&gt;file position = 21630761&lt;BR /&gt;file size = 21630761&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk/metrics.log&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/metrics.log.1&lt;BR /&gt;file position = 25000026&lt;BR /&gt;file size = 25000026&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/metrics.log.2&lt;BR /&gt;file position = 25000081&lt;BR /&gt;file size = 25000081&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/mongod.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/remote_searches.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/scheduler.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/search_messages.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/searchhistory.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunk_instrumentation_cloud.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd-utility.log&lt;BR /&gt;file position = 69012&lt;BR /&gt;file size = 69012&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd.log&lt;BR /&gt;file position = 12378562&lt;BR /&gt;file size = 12378562&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk/splunkd.log&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = open file&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd_access.log&lt;BR /&gt;file position = 44571&lt;BR /&gt;file size = 44571&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = open file&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd_stderr.log&lt;BR /&gt;file position = 200&lt;BR /&gt;file size = 200&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd_stdout.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/splunkd_ui_access.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/splunk/wlm_monitor.log&lt;BR /&gt;file position = 0&lt;BR /&gt;file size = 0&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/splunk&lt;BR /&gt;percent = 100&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/var/log/watchdog/watchdog.log&lt;BR /&gt;file position = 12202&lt;BR /&gt;file size = 12202&lt;BR /&gt;parent = $SPLUNK_HOME/var/log/watchdog/watchdog.log*&lt;BR /&gt;percent = 100.00&lt;BR /&gt;type = finished reading&lt;/P&gt;&lt;P&gt;tcp_cooked:listenerports :&lt;BR /&gt;8089&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 16:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740950#M21789</guid>
      <dc:creator>Namdev</dc:creator>
      <dc:date>2025-03-05T16:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder monitoring issue for /opt/log/&lt;file name&gt;</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740953#M21790</link>
      <description>&lt;P&gt;This shows&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/log/
type = directory

/opt/log/cisco_ironport_web.log
file position = 207575
file size = 207575
parent = /opt/log/
percent = 100.00
type = finished reading&lt;/LI-CODE&gt;&lt;P&gt;that splunk has read this one log file 100%. This means that it had sent it to indexers (I suppose that this has defined in your inputs.conf).&amp;nbsp;&lt;BR /&gt;Why you don’t see those? There could be several reasons for that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;wrong timestamp recognition&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;wrong index definition&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;you have some transformations for drop those&lt;/LI&gt;&lt;LI&gt;something else&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;To tell the real reason you should try to query those e.g.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=* earliest=1 latest=+5y&lt;/LI-CODE&gt;&lt;P&gt;that shows if those have wrong time or those have gone to wrong index.&lt;/P&gt;&lt;P&gt;You should also check all conf files from UF to indexers and SH to see if there is something weird.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 18:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SplunkForwarder-monitoring-issue-for-opt-log-lt-file-name-gt/m-p/740953#M21790</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-05T18:01:48Z</dc:date>
    </item>
  </channel>
</rss>

