<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk is not logging data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501583#M100003</link>
    <description>&lt;P&gt;We have to know more about your Splunk environment to offer specific help, but there are some things you can check.&lt;BR /&gt;
Are the forwarders still running?&lt;BR /&gt;
Is the data source still producing events?&lt;BR /&gt;
If the data comes from a monitored file, is the file still present and has permissions allowing Splunk to read it?&lt;BR /&gt;
Did any network changes happen that might prevent the data from getting to the indexer(s)?&lt;BR /&gt;
Are there any errors in splunkd.log that might indicate a problem getting data in?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 13:01:08 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-12-05T13:01:08Z</dc:date>
    <item>
      <title>Splunk is not logging data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501582#M100002</link>
      <description>&lt;P&gt;User complained that Splunk is not logging data&lt;/P&gt;

&lt;P&gt;Data being stopped logging after 1:40 PM on Tue Dec 3rd.&lt;/P&gt;

&lt;P&gt;Please help me in resolving the problem.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8047i6BD6126D72F044EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 06:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501582#M100002</guid>
      <dc:creator>pratapa</dc:creator>
      <dc:date>2019-12-05T06:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not logging data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501583#M100003</link>
      <description>&lt;P&gt;We have to know more about your Splunk environment to offer specific help, but there are some things you can check.&lt;BR /&gt;
Are the forwarders still running?&lt;BR /&gt;
Is the data source still producing events?&lt;BR /&gt;
If the data comes from a monitored file, is the file still present and has permissions allowing Splunk to read it?&lt;BR /&gt;
Did any network changes happen that might prevent the data from getting to the indexer(s)?&lt;BR /&gt;
Are there any errors in splunkd.log that might indicate a problem getting data in?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501583#M100003</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-05T13:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not logging data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501584#M100004</link>
      <description>&lt;P&gt;Hi Pratapa,&lt;BR /&gt;
Can you please provide the type of logs ? &lt;BR /&gt;
Is it stopped from all the sources or Host or Sourcetype ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:01:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501584#M100004</guid>
      <dc:creator>kartm2020</dc:creator>
      <dc:date>2019-12-05T13:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not logging data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501585#M100005</link>
      <description>&lt;P&gt;Hi @pratapa,&lt;BR /&gt;
there could be many reasons because your Splunk doesn't receive data, you should debug point by point all your architecture:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;in the last day, there was any change in configuration (roles, grants, deployed TAs)?&lt;/LI&gt;
&lt;LI&gt;another user (e.g. admin) can see all the data?&lt;/LI&gt;
&lt;LI&gt;is there any block in firewall routes between Universal Forwarder and Splunk Server?&lt;/LI&gt;
&lt;LI&gt;from that server, you're continuing to receive in the same period Splunk internal logs (&lt;CODE&gt;index=_internal host=your_host&lt;/CODE&gt;)?&lt;/LI&gt;
&lt;LI&gt;the target server created the new logs?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Then check the inputs.conf deployed to that server.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-logging-data/m-p/501585#M100005</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-12-05T13:06:58Z</dc:date>
    </item>
  </channel>
</rss>

