<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Onboarding issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594647#M103921</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232545"&gt;@blbr123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some little question to better understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are you trying to read logs on the same Splunk server or in a different target server (using Universal Forwarder)?&lt;/LI&gt;&lt;LI&gt;the running Splunk user has the rights on that folder?&lt;/LI&gt;&lt;LI&gt;what does it happen if you run by cli the following command: "ls -la&amp;nbsp;&lt;SPAN&gt;/opt/sw/ss/splunklogs/archive.log.*.*"?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 11:58:58 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-04-21T11:58:58Z</dc:date>
    <item>
      <title>Data Onboarding issue- unable to see the data in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594644#M103920</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I have configured the inputs and props but unable to see the data in splunk.&lt;/P&gt;
&lt;P&gt;I have around 20 monitor stanza and all of them have same source type, below is my monitor stanza&lt;/P&gt;
&lt;P&gt;File to be monitored is below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;archive.log.DYYYYMMDD.Tnnnnnn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[monitor:///opt/sw/ss/splunklogs/archive.log.*.*]&lt;/P&gt;
&lt;P&gt;index=abc&lt;/P&gt;
&lt;P&gt;disabled = 0&lt;/P&gt;
&lt;P&gt;sourcetype=es:test:sd:logs&lt;/P&gt;
&lt;P&gt;Sample log file is below:&lt;/P&gt;
&lt;P&gt;where YYYYMMDD-Date ex-20220412&lt;/P&gt;
&lt;P&gt;nnnnnn-6 digit timestamp ex- 171300&lt;/P&gt;
&lt;P&gt;Below is props conf&lt;/P&gt;
&lt;P&gt;[es:test:sd:logs]&lt;/P&gt;
&lt;P&gt;SHOULD_LINEMERGE=true&lt;/P&gt;
&lt;P&gt;BREAK_ONLY_BEFORE= ^[\d+\-\d+\-\d+\s+\d+\d:+\d+:\d+.\d+\d+]&lt;/P&gt;
&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD=28&lt;/P&gt;
&lt;P&gt;TIME_FORMAT=%d-%m-%y %H:%M:%S.%N&lt;/P&gt;
&lt;P&gt;TIME_PREFIX=^\w&lt;/P&gt;
&lt;P&gt;Below is the data on which REGEX was done.&lt;/P&gt;
&lt;P&gt;[2022-04-04 23:10:30.643]&lt;/P&gt;
&lt;P&gt;Please let me know if there anything wrong in my configurations&lt;/P&gt;
&lt;P&gt;in internal logs for log level error it shows below error.&lt;/P&gt;
&lt;P&gt;StreamId:123456 had parsing error:unexpected character while expecting ' : ' :&amp;nbsp; ' , '&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 14:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594644#M103920</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-04-21T14:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594647#M103921</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232545"&gt;@blbr123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some little question to better understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are you trying to read logs on the same Splunk server or in a different target server (using Universal Forwarder)?&lt;/LI&gt;&lt;LI&gt;the running Splunk user has the rights on that folder?&lt;/LI&gt;&lt;LI&gt;what does it happen if you run by cli the following command: "ls -la&amp;nbsp;&lt;SPAN&gt;/opt/sw/ss/splunklogs/archive.log.*.*"?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 11:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594647#M103921</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-21T11:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594652#M103922</link>
      <description>&lt;P&gt;I am not sure it is your whole issue, but your time format doesn't match the example:&amp;nbsp;&lt;SPAN&gt;[2022-04-04 23:10:30.643]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It should be %Y-%m-%d %H:%M:%S.%N&lt;BR /&gt;&lt;BR /&gt;I would also add in a&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;LINE_BREAKER = &amp;lt;REGEX&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594652#M103922</guid>
      <dc:creator>sperkins</dc:creator>
      <dc:date>2022-04-21T12:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594657#M103923</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to read logs from another host using universal forwarder.&lt;/P&gt;&lt;P&gt;Yes the splunk user has the read access to the log paths and files.&lt;/P&gt;&lt;P&gt;Cannot check third one as user is not available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594657#M103923</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-04-21T12:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594665#M103926</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232545"&gt;@blbr123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the third check is a linux command to check if the path you're using is correct that you have to run using an SSH terminal.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ls -la /opt/sw/ss/splunklogs/archive.log.*.*&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594665#M103926</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-21T12:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594790#M103938</link>
      <description>&lt;P&gt;i get this output when i run the command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-rw-r----- 1 abc xyz 716 Apr 22 01:16&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 05:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594790#M103938</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-04-22T05:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594796#M103939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232545"&gt;@blbr123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if "xyz" is the file that you want to monitor the command in the stanza is correct.&lt;/P&gt;&lt;P&gt;did you see in Splunk Enterprise server the internal Splunk logs from that server?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;if not there's a problem in connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 06:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594796#M103939</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-22T06:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594802#M103940</link>
      <description>&lt;P&gt;There are 2 hots sending the logs:&lt;/P&gt;&lt;P&gt;and can see the internal logs for both the hosts.&lt;/P&gt;&lt;P&gt;For one of the hosts it gives error in internal logs: for log_level WARN&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;TcpOutEloop&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Connect&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt;&amp;nbsp;x:x:x:x&lt;SPAN class=""&gt;:9997&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Connection&lt;/SPAN&gt; &lt;SPAN class=""&gt;refused&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;for log_level ERROR getting below error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;StreamId:1234567 had parsing error:Unexpected character while expecting ':': ',' - data_source="/opt/splunkforwarder/var/spool/splunk/tracker.log"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Does this indicate something wrong for monitoring?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 06:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594802#M103940</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-04-22T06:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594807#M103941</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232545"&gt;@blbr123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the error message says that there's a connection problem, but&amp;nbsp;I don't see any configuration error (except the one indicated by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244626"&gt;@sperkins&lt;/a&gt;).&lt;/P&gt;&lt;P&gt;if you're receiving the Splunk internal logs from that Universal Forwarder the connection is correctly established, are you sure about internal logs?&lt;/P&gt;&lt;P&gt;What does it happen if you use a larger time period (e.g. always)?&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 07:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594807#M103941</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-22T07:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594812#M103942</link>
      <description>&lt;P&gt;when i select always i get below error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FilesystemChangeWatcher [xxxxxx MainTailingThread] - error getting attributes of path "/opt/sw/ss/splunklogs/system.log.xxxxxxxxx.xxxxxx": Permission denied&lt;/P&gt;&lt;P&gt;Insufficient permissions to read file='/opt/sw/ss/si/install/logs/noapp.log.xxxx.xxxx' (hint: Permission denied , UID: xxxxxx, GID: xxxxxxx)&lt;/P&gt;&lt;P&gt;and the user has changed the permission to read the files for splunk user, and i have added restartSplunkd=true in server class to restart the splunk service for changes to be applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still same issue&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 07:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-issue-unable-to-see-the-data-in-splunk/m-p/594812#M103942</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-04-22T07:38:17Z</dc:date>
    </item>
  </channel>
</rss>

