<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why doesn't My heavy forwarder pull a certain log file in? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605225#M105210</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a heavy forwarder install on a server to monitor a certain log file. We used to read that log just fine, but after some bug fixed about log generation(on server side) and that server restart, I can't read that log file at all.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our inputs.conf was&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor:///data/ESB/ACH/LOG/]
disabled = 0
sourcetype = napas.itso.app.achlog	
index = napas.ach.app.log&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it still can read all the logs file in there, but can't read the one that we need. I have restarted the agent, restart the server and restart splunkd connection but it still can't read the one that we need.&lt;/P&gt;
&lt;P&gt;We can read&lt;/P&gt;
&lt;P&gt;/data/ESB/ACH/LOG/iib_log_summary_2022-07-12.log&lt;/P&gt;
&lt;P&gt;but can't read&lt;/P&gt;
&lt;P&gt;/data/ESB/ACH/LOG/iib_log_detail_2022-07-12.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We check the read permission on both file but they're the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 911px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20485i755972BDF38C566B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;How can I troubleshoot it?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2022 13:51:15 GMT</pubDate>
    <dc:creator>phamxuantung</dc:creator>
    <dc:date>2022-07-12T13:51:15Z</dc:date>
    <item>
      <title>Why doesn't My heavy forwarder pull a certain log file in?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605225#M105210</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a heavy forwarder install on a server to monitor a certain log file. We used to read that log just fine, but after some bug fixed about log generation(on server side) and that server restart, I can't read that log file at all.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our inputs.conf was&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor:///data/ESB/ACH/LOG/]
disabled = 0
sourcetype = napas.itso.app.achlog	
index = napas.ach.app.log&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it still can read all the logs file in there, but can't read the one that we need. I have restarted the agent, restart the server and restart splunkd connection but it still can't read the one that we need.&lt;/P&gt;
&lt;P&gt;We can read&lt;/P&gt;
&lt;P&gt;/data/ESB/ACH/LOG/iib_log_summary_2022-07-12.log&lt;/P&gt;
&lt;P&gt;but can't read&lt;/P&gt;
&lt;P&gt;/data/ESB/ACH/LOG/iib_log_detail_2022-07-12.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We check the read permission on both file but they're the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 911px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20485i755972BDF38C566B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;How can I troubleshoot it?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 13:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605225#M105210</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-07-12T13:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: My heavy forwarder don't pull a certain log file in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605235#M105215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk doesn't read a file twice even if the file has the same name..&lt;/P&gt;&lt;P&gt;So maybe the content of the unread file was already read.&lt;/P&gt;&lt;P&gt;You can check if the content of the file was already indexed searching for the content of the file.&lt;/P&gt;&lt;P&gt;You can force Splunk to index the file&amp;nbsp;adding a dedicated stanza with the crcSal option:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///data/ESB/ACH/LOG/iib_log_detail_2022-07-12.log]
disabled = 0
sourcetype = napas.itso.app.achlog	
index = napas.ach.app.log
crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 06:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605235#M105215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-12T06:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: My heavy forwarder don't pull a certain log file in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605241#M105216</link>
      <description>&lt;P&gt;As you could see, the file that I want to read will have a different name each day, with default name will be iib_log_detail&amp;lt;day&amp;gt;.log (today log is "iib_log_detail_2022-07-12.log" and tomorrow will be "iib_log_detail_2022-07-13.log").&lt;/P&gt;&lt;P&gt;I added your stanza as well as one another as show&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="stanza.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20487i88553B97B7C4D3FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="stanza.PNG" alt="stanza.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After restart Splunkd, search that index and count by source, it still wouldn't show up&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="source.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20488iAB7B7AFEBCE19B3A/image-size/large?v=v2&amp;amp;px=999" role="button" title="source.PNG" alt="source.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 07:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605241#M105216</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-07-12T07:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: My heavy forwarder don't pull a certain log file in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605244#M105217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the different name is relevant only if you use the crcSalt option otherwise it isn't relevant: if the file content was already indexed it isn't indexed twice, even if the filename is different!&lt;/P&gt;&lt;P&gt;If you continue to not find the file also after adding the new stanza, please, try to search the file in all time, maybe there's a timestamp parsing error, in other words, search in all time&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| metasearch index=napas.ach.app.log source="*iib_log_detail_*.log"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 07:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605244#M105217</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-12T07:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: My heavy forwarder don't pull a certain log file in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605253#M105219</link>
      <description>&lt;P&gt;I run the query you provide on All time and don't see the file, so it's not in the index.&lt;/P&gt;&lt;P&gt;I check the log file itself, the latest one I received was iib_log_detail_2022-07-04.log (8 days ago), the file structure is the same with iib_log_detail_2022-07-12.log so I don't think there's a timestamp parsing error.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 08:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605253#M105219</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-07-12T08:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: My heavy forwarder don't pull a certain log file in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605256#M105221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sorry, I haven't any other idea to identify your issue!&lt;/P&gt;&lt;P&gt;Last try: rename the unread file and modify the stanza in inputs.conf pointing to the new file.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 08:21:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-doesn-t-My-heavy-forwarder-pull-a-certain-log-file-in/m-p/605256#M105221</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-12T08:21:46Z</dc:date>
    </item>
  </channel>
</rss>

