<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting a file monitor on Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582680#M102650</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234669"&gt;@mike_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you surely checked that you're receiving other data from that UF (index=_internal host=&amp;lt;your_host&amp;gt;).&lt;/P&gt;&lt;P&gt;If yes, please check if the new version was deployed and manually restart Splunk on Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jan 2022 07:13:42 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-01-27T07:13:42Z</dc:date>
    <item>
      <title>Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582361#M102605</link>
      <description>&lt;P&gt;I currently have a Universal Forwarder running on a linux syslog server with a bunch of file monitors in place such as:&lt;/P&gt;&lt;P&gt;[monitor:///var/log/10.10.10.99/syslog.log]index=hphost_segment=3disabled=0&lt;/P&gt;&lt;P&gt;The index that i'm using for my new file monitor stanzas is a newly created index, that i haven't used previously.&lt;/P&gt;&lt;P&gt;I've created a couple of new deployment apps with the new file monitors and pushed them out to the UF on my syslog server. I can see other monitored files on the syslog server being forwarded into Splunk, however i'm not seeing my new files being monitored.&lt;/P&gt;&lt;P&gt;I've reloaded the deploy-server to ensure that the configs are being pushed out. I have also run a "./splunk btool inputs list" command and I can see that it is listing my new configuration as a part of the aggregated inputs.conf. However i'm not seeing any events for these new file monitors being forwarded into Splunk. The new index is showing 0 events received.&lt;/P&gt;&lt;P&gt;Is there a way to list events being outputted by the Universal Forwarder? Also is there a way to list events from my Universal Forwarder that are hitting the input queue on my Splunk indexer?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 06:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582361#M102605</guid>
      <dc:creator>mike_k</dc:creator>
      <dc:date>2022-01-25T06:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582362#M102606</link>
      <description>&lt;P&gt;i&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234669"&gt;@mike_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one question: did you configured a restart in ServerClass when App is updated?&lt;/P&gt;&lt;P&gt;by default, in a deployment server, local Splunk restart is disabled and you have to manually enable in the ServerClass.&lt;/P&gt;&lt;P&gt;You can check this on the Deployment Server.&lt;/P&gt;&lt;P&gt;Then you can quicly check if this is the problem on the target server, checking if the new input was deployed and manually restarting&amp;nbsp; Splunk on the target server.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 07:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582362#M102606</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-25T07:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582366#M102608</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;this is just like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said. For some reason, default is not to restart splunkd on target server. If you log to target and use btool, then you are seeing what configuration you have on disk, not what is currently in use. To see this you must use command “splunk show config”. If/when the missing restart was the reason, then just update that package e.g. add empty line in config + update version information. Then edit configuration on DS’s gui to ensure that you have checked restart and then redeploy it to all needed targets.&amp;nbsp;&lt;BR /&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 07:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582366#M102608</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-25T07:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582665#M102644</link>
      <description>&lt;P&gt;Thanks for those replies &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; . Sorry i should have included that info in my original post :-/.&lt;/P&gt;&lt;P&gt;I did make sure that both "Enable App" and "Restart Splunkd" were enabled on the app before i pushed it out to the Universal Forwarder. To make doubly sure, i did as you suggested and added a comment line to my inputs.conf file and then reloaded the deployment server. However still don't seem to be getting any data in from those new file monitors i added.&lt;/P&gt;&lt;P&gt;For some reason I am unable to run the "splunk show config inputs" command. It prompts me for username/password and then gives me a login failed .. i'll have to look into that.&lt;/P&gt;&lt;P&gt;I also tied running the following search on my Search Head:&lt;/P&gt;&lt;P&gt;"index=_internal host="syslog_server_ip" group=per_source_thruput | stats count by series" which i think should be showing me what monitored files on the syslog server are coming through to my indexer, however it is not listing the new files that i am trying to monitor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 05:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582665#M102644</guid>
      <dc:creator>mike_k</dc:creator>
      <dc:date>2022-01-27T05:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582673#M102647</link>
      <description>&lt;P&gt;You probably need to create account on UF's splunk to run this command if you don't know it's admin account. Just look how to update admin pass from google (use user-seed.conf).&lt;/P&gt;&lt;P&gt;Have you look UF's internal log files to see if there is anything interesting?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 06:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582673#M102647</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-27T06:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582680#M102650</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234669"&gt;@mike_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you surely checked that you're receiving other data from that UF (index=_internal host=&amp;lt;your_host&amp;gt;).&lt;/P&gt;&lt;P&gt;If yes, please check if the new version was deployed and manually restart Splunk on Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 07:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582680#M102650</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-27T07:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582834#M102699</link>
      <description>&lt;P&gt;Thanks. Where abouts does the UF store it’s log files locally?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 21:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582834#M102699</guid>
      <dc:creator>mike_k</dc:creator>
      <dc:date>2022-01-27T21:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582835#M102700</link>
      <description>&lt;P&gt;Locally you found those logs under directory /opt/splunkforwarder/var/log/splunk&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 21:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582835#M102700</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-27T21:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582859#M102701</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234669"&gt;@mike_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk logs are (in all Splunk installation) at $SPLUNK_HOME/var/log/splunk.&lt;/P&gt;&lt;P&gt;You can also see the Forwarder's logs in Splunk search running&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;If you haven't them, probably there's a problem in log forwarding, the one I hinted to search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 07:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/582859#M102701</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-28T07:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/583160#M102756</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;, &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; Thanks for those comments. They got me looking in the right direction. I looked through the UF logs and found a whole bunch of messages as follows:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#993300"&gt;WARN FilesystemChangeWatcher - error reading directory "/var/log/&amp;lt;ip_address_of_server&amp;gt;" Permission denied.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Had to go through and change the permissions for the syslog directories/files so that the "splunk" user could access these directories/files. Used Linux command &lt;FONT color="#993300"&gt;"setfacl -R -m u:splunk:r-x /var/log/&amp;lt;ip_address_of_server" &lt;FONT color="#000000"&gt;to do this&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Once i had done this, the logs started populating in Splunk correctly.&lt;/P&gt;&lt;P&gt;Now when i look through the logs, i'm not seeing any further permission denied statements.&lt;/P&gt;&lt;P&gt;I am seeing some warning messages:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#993300"&gt;"ThruputProcessor - Current Data throughput (258kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;So i suspect that i may need to increase my maxKBps (which is still set at default 256kbps) to take into account the increased logging, however will wait to see whether it settles down once it has finished doing the initial file ingestion.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 04:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/583160#M102756</guid>
      <dc:creator>mike_k</dc:creator>
      <dc:date>2022-02-01T04:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a file monitor on Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/583217#M102765</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234669"&gt;@mike_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the default for &lt;SPAN&gt;maxKBps&amp;nbsp;is 256k for Universal Forwarders, if you have bandwidth availability, you can set this parameter and improve the quantity of logs sent to Indexers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 13:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Troubleshooting-a-file-monitor-on-Universal-Forwarder/m-p/583217#M102765</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-01T13:22:10Z</dc:date>
    </item>
  </channel>
</rss>

