<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with Universal Forwarder forwarding logs to index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598876#M104439</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241735"&gt;@Poojitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as you can read at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp;and in many other videos, you have to do some preventive actions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you already enable log receiving on Indexers [Settings -- Forwarderding and Receiving -- Receiving]?&lt;/LI&gt;&lt;LI&gt;did you already enable log forwarding on Universal Forwarder (outputs.conf or installation procedure)?&lt;/LI&gt;&lt;LI&gt;do you see internal logs from that Forwarders on Splunk (index=_internal host=&amp;lt;your_host&amp;gt;)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 09:53:30 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-05-23T09:53:30Z</dc:date>
    <item>
      <title>Why is there issue with Universal Forwarder forwarding logs to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598864#M104438</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I have installed splunk UF on windows . I have one static log file in system (json)&amp;nbsp; and that need to be monitored.&amp;nbsp; &amp;nbsp;I have configure this in inputs.conf file.&lt;BR /&gt;I see only system/application and security logs being sent to indexer whereas the static log file is not seen.&lt;BR /&gt;&lt;BR /&gt;I ran "splunk list inputstatus" and checked,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;C:\Users\Administrator\Downloads\test\test.json
file position = 75256
file size = 75256
percent = 100.00
type = finished reading&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, this means the file is being read properly.&lt;BR /&gt;&lt;BR /&gt;What can be the issue that I dont see test.json logs at splunk side ? I tried checking index=_internal at indexer but not able to figure out what is causing issue, I checked few blogs on Internet as well. Can anyone please help on this.&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance,&lt;BR /&gt;Newbie to splunk&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 15:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598864#M104438</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2022-05-24T15:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598876#M104439</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241735"&gt;@Poojitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as you can read at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp;and in many other videos, you have to do some preventive actions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you already enable log receiving on Indexers [Settings -- Forwarderding and Receiving -- Receiving]?&lt;/LI&gt;&lt;LI&gt;did you already enable log forwarding on Universal Forwarder (outputs.conf or installation procedure)?&lt;/LI&gt;&lt;LI&gt;do you see internal logs from that Forwarders on Splunk (index=_internal host=&amp;lt;your_host&amp;gt;)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 09:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598876#M104439</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-23T09:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598919#M104442</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thanks for your response&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Yes, I have enabled it. I see system, application and security logs from that windows machine but not the log from the static file.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Yes , I have enabled&lt;/LI&gt;&lt;LI&gt;Yes, I checked index=_internal , there are logs from this host.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Searching the index=_internal and this host with the filename (test.json), I see nix_errors with tag=error :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;active_searches=15, elapsedTime=0.604, search='pretypeahead
prefix="index=_internal \"test_sourcetype\" \"test-host\" \"test.json
max_time="1" count="50" use_cache=1', savedsearch_name="", drop_count=0, scan_count=0, eliminated_buckets=0, considered_events=0, decompressed_slices=0, events_count=0, total_slices=0, considered_buckets=0, search_rawdata_bucketcache_error=0, search_rawdata_bucketcache_miss=0, search_index_bucketcache_error=0, search_index_bucketcache_hit=0, search_index_bucketcache_miss=0, search_rawdata_bucketcache_hit=0, search_rawdata_bucketcache_miss_wait=0.000, search_index_bucketcache_miss_wait=0.000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does this imply ? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 14:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598919#M104442</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2022-05-23T14:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598920#M104443</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241735"&gt;@Poojitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the above tests were to understand if the connection id correctly establishhed.&lt;/P&gt;&lt;P&gt;Now, could you share your inputs.conf where the file is monitored?&lt;/P&gt;&lt;P&gt;&amp;nbsp;in other words, a file called "inputs.conf" where is located a stanza with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://C:\Users\Administrator\Downloads\test\test.json]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598920#M104443</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-23T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598923#M104444</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Application]
disabled = 0
index = test_index
sourcetype = test_sourcetype
 
[WinEventLog://Security]
disabled = 0
index = test_index
sourcetype = test_sourcetype
 
[WinEventLog://System]
disabled = 0
index = test_index
sourcetype = test_sourcetype

[monitor://C:\Users\Administrator\Downloads\test\log.json]
disabled = 0
index = test_index
sourcetype = test_sourcetype&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is what my inputs.conf file&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598923#M104444</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2022-05-23T15:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598925#M104445</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241735"&gt;@Poojitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk doesn't read twice a log, maybe your log was already read, could you try to add this row to ste stanza of your inputs.conf and restart Splunk on Forwarder?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSal = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598925#M104445</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-23T15:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598940#M104449</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Application]
disabled = 0
index = test_index
sourcetype = test_sourcetype
 
[WinEventLog://Security]
disabled = 0
index = test_index
sourcetype = test_sourcetype
 
[WinEventLog://System]
disabled = 0
index = test_index
sourcetype = test_sourcetype

[monitor://C:\Users\Administrator\Downloads\test\log.json]
disabled = 0
index = test_index
sourcetype = test_sourcetype&lt;/LI-CODE&gt;&lt;P&gt;This is how my inputs.conf file looks like&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 16:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598940#M104449</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2022-05-23T16:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598961#M104452</link>
      <description>&lt;P&gt;I tried this, its not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 18:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/598961#M104452</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2022-05-23T18:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Universal Forwarder forwarding logs to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/599011#M104460</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241735"&gt;@Poojitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry: I missed a char!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 06:26:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-there-issue-with-Universal-Forwarder-forwarding-logs-to/m-p/599011#M104460</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-24T06:26:51Z</dc:date>
    </item>
  </channel>
</rss>

