<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SplunkForwarder abruptly stop forwarding logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570872#M101152</link>
    <description>&lt;P&gt;Hi guys... I have a splunk forwarder instance v8.2.1 on a AIX server. I have a custom app configured on which I am monitoring a few logs and forwarding them to an indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having a weird problem where the forwarder stops sending data every day at 1 PM and resumes sending data feed at 1 AM. So, I would have no data consumed between 1 PM to 1AM. Any suggestions on what could be the issue ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am also forwarding splunkd.log to the same indexers and I see that log data all thru the day. The issue I am facing is only with one of the custom app I have on this instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sharing inputs.conf and props.conf entries&amp;nbsp;&lt;/P&gt;&lt;P&gt;========== inputs.conf =========&lt;/P&gt;&lt;P&gt;[monitor:///log/mycustomereport/mycustomereport.log*]&lt;BR /&gt;disabled = false&lt;BR /&gt;followTail = 0&lt;BR /&gt;sourcetype =mycustomereport&lt;BR /&gt;blacklist = \.gz&lt;BR /&gt;index = 20000_java_app_idx&lt;BR /&gt;ignoreOlderThan=2h&lt;/P&gt;&lt;P&gt;========== props.conf =========&lt;/P&gt;&lt;P&gt;[mycustomereport]&lt;BR /&gt;TIME_PREFIX=\w+\|&lt;BR /&gt;TIME_FORMAT=%m/%d/%Y %I:%M:%S %3Q %p&lt;BR /&gt;TRUNCATE = 0&lt;BR /&gt;MAX_EVENTS = 10000&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\n\r]+)mycustomereport&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 40&lt;/P&gt;&lt;P&gt;PS: I do see that log file I am monitoring is having data written to it consistently.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did enable debug logs... i dont see anything written which could helped me understand the issue. I also dont see any crash file generated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 23:00:49 GMT</pubDate>
    <dc:creator>vik</dc:creator>
    <dc:date>2021-10-13T23:00:49Z</dc:date>
    <item>
      <title>SplunkForwarder abruptly stop forwarding logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570872#M101152</link>
      <description>&lt;P&gt;Hi guys... I have a splunk forwarder instance v8.2.1 on a AIX server. I have a custom app configured on which I am monitoring a few logs and forwarding them to an indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having a weird problem where the forwarder stops sending data every day at 1 PM and resumes sending data feed at 1 AM. So, I would have no data consumed between 1 PM to 1AM. Any suggestions on what could be the issue ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am also forwarding splunkd.log to the same indexers and I see that log data all thru the day. The issue I am facing is only with one of the custom app I have on this instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sharing inputs.conf and props.conf entries&amp;nbsp;&lt;/P&gt;&lt;P&gt;========== inputs.conf =========&lt;/P&gt;&lt;P&gt;[monitor:///log/mycustomereport/mycustomereport.log*]&lt;BR /&gt;disabled = false&lt;BR /&gt;followTail = 0&lt;BR /&gt;sourcetype =mycustomereport&lt;BR /&gt;blacklist = \.gz&lt;BR /&gt;index = 20000_java_app_idx&lt;BR /&gt;ignoreOlderThan=2h&lt;/P&gt;&lt;P&gt;========== props.conf =========&lt;/P&gt;&lt;P&gt;[mycustomereport]&lt;BR /&gt;TIME_PREFIX=\w+\|&lt;BR /&gt;TIME_FORMAT=%m/%d/%Y %I:%M:%S %3Q %p&lt;BR /&gt;TRUNCATE = 0&lt;BR /&gt;MAX_EVENTS = 10000&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\n\r]+)mycustomereport&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 40&lt;/P&gt;&lt;P&gt;PS: I do see that log file I am monitoring is having data written to it consistently.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did enable debug logs... i dont see anything written which could helped me understand the issue. I also dont see any crash file generated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 23:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570872#M101152</guid>
      <dc:creator>vik</dc:creator>
      <dc:date>2021-10-13T23:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder abruptly stop forwarding logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570874#M101154</link>
      <description>&lt;P&gt;Is there a process that restarts the UF at 1am?&lt;/P&gt;&lt;P&gt;Why &lt;FONT face="courier new,courier"&gt;ignoreOlderThan=2h&lt;/FONT&gt;?&amp;nbsp; If the log file's mod time ever becomes 2 hours old the log file will be ignored until the UF restarts.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 00:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570874#M101154</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-14T00:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder abruptly stop forwarding logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570876#M101155</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file is constantly updated with data. I did try removing&amp;nbsp;&lt;SPAN&gt;ignoreOlderThan. But I didn't&amp;nbsp;see the logs flow.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;UF does not have any scheduled restarts at 1AM. The process runs for days without any restart but still has the same same behavior&amp;nbsp;every single day.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 00:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-abruptly-stop-forwarding-logs/m-p/570876#M101155</guid>
      <dc:creator>vik</dc:creator>
      <dc:date>2021-10-14T00:11:40Z</dc:date>
    </item>
  </channel>
</rss>

