<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk configuration issue in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486460#M24470</link>
    <description>&lt;P&gt;I understand your inputs configuration is correct and the UF is forwarding other data.&lt;BR /&gt;
Have you tried searching the future (latest=+1y) in case there's an error parsing dates?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2020 16:17:19 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-01-14T16:17:19Z</dc:date>
    <item>
      <title>Splunk configuration issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486457#M24467</link>
      <description>&lt;P&gt;Greetings!!&lt;/P&gt;

&lt;P&gt;help me on the following questions: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;I would like to ask about Splunk configuration issue of not getting logs after doing configuration. i have added new data inputs in inputs.conf as  i always does and  I have already done /opt/splunk/bin/splunk reload deploy-server BUT the problem am not getting the logs in Splunk GUI ??? &lt;BR /&gt;
index= xxx host="y.y.y.y", i can't get its logs??? &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;what the best way to do when opt/syslog directory is almost full??&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 13 Jan 2020 09:26:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486457#M24467</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-01-13T09:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configuration issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486458#M24468</link>
      <description>&lt;P&gt;Verify the user running the UF has read access to the logs.&lt;BR /&gt;
Verify the settings in inputs.conf, including &lt;CODE&gt;index=&lt;/CODE&gt; and &lt;CODE&gt;sourcetype=&lt;/CODE&gt;  are correct.&lt;BR /&gt;
Verify the UF can connect to the indexer(s).&lt;BR /&gt;
Make sure your search is looking for the right sourcetype in the right index.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 13:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486458#M24468</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-13T13:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configuration issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486459#M24469</link>
      <description>&lt;P&gt;Hi richgalloway?&lt;/P&gt;

&lt;P&gt;Thank you for the quick response,&lt;BR /&gt;
I have verified the settings in inputs.conf all are included correctly,&lt;BR /&gt;
am  getting logs from Syslog sender(network devices), I think UF we use it when it is operating system to forward logs while here is configuration of syslog sender , even when am searching index=xx , i can't find its data?&lt;BR /&gt;
only i see it when i set the time before the configuration at this point i see the logs but after configuration i can't see that index??&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 08:50:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486459#M24469</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-01-14T08:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configuration issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486460#M24470</link>
      <description>&lt;P&gt;I understand your inputs configuration is correct and the UF is forwarding other data.&lt;BR /&gt;
Have you tried searching the future (latest=+1y) in case there's an error parsing dates?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 16:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-configuration-issue/m-p/486460#M24470</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-14T16:17:19Z</dc:date>
    </item>
  </channel>
</rss>

