<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How are logs appearing on a particular source type in heavy forwarder? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/511262#M2827</link>
    <description>&lt;P&gt;Yes, that should be it. If there is no configuration for index or other parameters, it will be picked up from the default&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 06:28:45 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2020-07-28T06:28:45Z</dc:date>
    <item>
      <title>How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510550#M2755</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; In my heavy forwarder I am trying to understand how logs are appearing on a particular source type.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I go to&amp;nbsp; Settings &amp;lt; source type&amp;lt; and search for it. I find it. I edit it. But it's not telling me any detail on how those .csv files from the various host are getting the file to the heavy forwarder.&lt;/P&gt;
&lt;P&gt;The universal forwarder inputs.conf file on the host does not reference the .csv files.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anything else I can do on the heavy forwarder to find out how the host are sending to it? It's not syslog.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 03:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510550#M2755</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-07-23T03:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510574#M2758</link>
      <description>&lt;P&gt;Are you indexing the events on HF or forwarding it to indexer?&lt;/P&gt;&lt;P&gt;While searching for the events , doesn't the "source" field has information about source of the data and "host" field about the machine from where the events are pushed?&lt;/P&gt;&lt;P&gt;Do you have web enabled on the HF and is there a possibility of manual upload ?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 04:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510574#M2758</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-23T04:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510579#M2759</link>
      <description>&lt;P&gt;The HF is forwarding to splunk cloud for indexing. No Indexing done on the HF&lt;/P&gt;&lt;P&gt;While searching the event the source is:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\monitor\splunk.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The CSV does exist on the host.&amp;nbsp; My question is, how is the host sending this csv file to the HF? I don't see anything in the input.conf file referencing this csv.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 05:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510579#M2759</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-07-23T05:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510769#M2785</link>
      <description>&lt;P&gt;Do you have only one UF and one HF and all the events are going through HF before hitting index?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the web enabled for HF and is there a possibility of direct upload using web ?&lt;/P&gt;&lt;P&gt;Also search in your _internal logs and check if you are able to find any activity regarding the file upload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 03:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510769#M2785</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-24T03:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510776#M2786</link>
      <description>&lt;P&gt;I have lots of UFs&amp;nbsp; (individual servers) and one HF.&amp;nbsp; &amp;nbsp;Yes all events from UFs are hitting the HF before getting indexed at the cloud.&lt;/P&gt;&lt;P&gt;Would you elaborate on what you mean by is the web enabled for HF and direct uploading?&lt;/P&gt;&lt;P&gt;On the HF I searched index=_internal and no data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 04:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510776#M2786</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-07-24T04:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510781#M2787</link>
      <description>&lt;P&gt;Within the HF &amp;lt; Settings &amp;lt; Data Inputs &amp;lt; Forwarded Inputs &amp;lt; Files and Directories &amp;lt;&amp;nbsp;&lt;BR /&gt;I see the source path c:\splunk\computers.csv there and it is ENABLED&lt;/P&gt;&lt;P&gt;Still doesn't answer my question about how this CSV is getting sent to the HF&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 04:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510781#M2787</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-07-24T04:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510821#M2790</link>
      <description>&lt;P&gt;"On the HF I searched index=_internal and no data" =&amp;gt; if you are not indexing in HF, you should search&amp;nbsp; (index=_internal) in search head which is connected to indexers&lt;/P&gt;&lt;P&gt;"Would you elaborate on what you mean by is the web enabled for HF and direct uploading?" =&amp;gt; If you have splunk web enabled on HF, users can login to the splunk web and upload data.&lt;/P&gt;&lt;P&gt;It could be on any of the forwarders or HFs&amp;nbsp; and the inputs.conf can be present in multiple places. Try splunk btool to list out the inputs conf stanzas on the machine from where the file is uploaded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 10:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/510821#M2790</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-24T10:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/511238#M2823</link>
      <description>&lt;P&gt;great suggestion on the btool. i found references of the .csv file in an inputs file under&lt;/P&gt;&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\ForwardedMonitor\local&lt;/P&gt;&lt;P&gt;I'm assuming if the stanza beings with MONITOR and then has path to the .csv and also a sourcetype specified, that would instruct the universal forwarder to send this file to the Heavy forwarder?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 22:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/511238#M2823</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-07-27T22:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: How are logs appearing on a particular source type in heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/511262#M2827</link>
      <description>&lt;P&gt;Yes, that should be it. If there is no configuration for index or other parameters, it will be picked up from the default&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 06:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-are-logs-appearing-on-a-particular-source-type-in-heavy/m-p/511262#M2827</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-28T06:28:45Z</dc:date>
    </item>
  </channel>
</rss>

