<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputs.conf not indexing /var/log/messages in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputs-conf-not-indexing-var-log-messages/m-p/614354#M106314</link>
    <description>&lt;P&gt;The most recent TA has inputs.conf like so for just for monitors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#Add-on upgrade 8.7 has new monitors.  Remark the old monitors and adding the current one.
[monitor:///Library/Logs]
disabled = 0
index = $someindex$

[monitor:///var/log]
whitelist=(\.log|log$|secure|messages|auth|mesg$|cron$|acpid$|\.out)
#customize aide.log$date$.gz file to excluded
blacklist=(aide.log-\d{8}.gz|anaconda\.syslog)
disabled = 0
index = $someindex$

[monitor:///var/adm]
whitelist=(\.log|log$|messages)
disabled = 0
index = $someindex$

[monitor:///etc]
whitelist=(\.conf|\.cfg|config$|\.ini|\.init|\.cf|\.cnf|shrc$|^ifcfg|\.profile|\.rc|\.rules|\.tab|tab$|\.login|policy$)
disabled = 0
index = $someindex$&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A1:&amp;nbsp; You just need to ingestion the current file not the pervious ones.&lt;BR /&gt;&lt;SPAN&gt;A2:&amp;nbsp; Using * is very wide net.&amp;nbsp; you should use a whitelist = $REX$&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A3. Work with Linux SA or look at the logs to figure out the cause of the kill.&amp;nbsp; Is a person or Job?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A4: I would recommend&amp;nbsp;what in the TA for messages&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Sep 2022 17:04:19 GMT</pubDate>
    <dc:creator>youngsuh</dc:creator>
    <dc:date>2022-09-23T17:04:19Z</dc:date>
    <item>
      <title>Why is inputs.conf not indexing /var/log/messages?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputs-conf-not-indexing-var-log-messages/m-p/614348#M106313</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a odd issue which seems to have been resolved but I would like to know the root cause of this issue.&lt;BR /&gt;I inherited a splunk configuration with one of the stanza entries in inputs.conf being:&lt;BR /&gt;[monitor:///var/log/messages*]&lt;BR /&gt;sourcetype=syslog&lt;BR /&gt;index = os&lt;BR /&gt;disabled = 0&lt;/P&gt;
&lt;P&gt;When I perform a ls -l on /var/log/messages* I get the below:&lt;BR /&gt;-rw-------. 1 root root 7520499 Sep 23 07:15 messages&lt;BR /&gt;-rw-------. 1 root root 4795535 Aug 28 01:45 messages-20220828&lt;BR /&gt;-rw-------. 1 root root 6636499 Sep 4 01:42 messages-20220904&lt;BR /&gt;...&lt;/P&gt;
&lt;P&gt;When I do a spl search on any of the possible sources, since the stanza uses "*", I get no results except for the source=messages.&lt;BR /&gt;I do not get results for the source=messages-20220828&lt;BR /&gt;(even if I extend the earliest=-365d).&lt;/P&gt;
&lt;P&gt;When the rsyslog executed and rotated the messages log file this past week, at about 2 am on saturday, splunk stopped indexing the messages log file.&lt;BR /&gt;the messages log file kept being populated by linux so that side seems to be working as expected.&lt;BR /&gt;the last log entry splunk recorded was:&lt;BR /&gt;_time = 2022-09-18 01:46:40&lt;BR /&gt;_raw = Sep 18 01:46:40 ba-dev-web rsyslogd: [origin software="rsyslogd" swVersion="8.24.0-57.el7_9.3" x-pid="1899" x-info="&lt;A href="http://www.rsyslog.com" target="_blank" rel="noopener"&gt;http://www.rsyslog.com&lt;/A&gt;"] rsyslogd was HUPed&lt;/P&gt;
&lt;P&gt;I restarted the splunkforwarder on the server with the issue and this fix the issue and splunk started indexing the messages log entries again.&lt;/P&gt;
&lt;P&gt;To attempt to create a permanent solution to this issue because restarting the forwarder manually is not a adequate solution for this issue I created the below stanza:&lt;BR /&gt;[monitor:///var/log/messages]&lt;BR /&gt;index = test&lt;BR /&gt;disabled = 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I do not believe I need the "*" because&lt;BR /&gt;1) messages* sources are not being indexed by splunk, so why use "*". (only source=messages).&lt;BR /&gt;2) we do not need to index messages backup log files.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When I came to work today, 18 hours after the "fix" (restart of splunk forwarder), my stanza is still working and indexing log entries as expected but the previous one:&lt;BR /&gt;[monitor:///var/log/messages*]&lt;BR /&gt;does not index log entries any more.&lt;/P&gt;
&lt;P&gt;I used the working one and determine that the last entries before splunk stopped indexing were:&lt;BR /&gt;first column is _time and next column is _raw&lt;BR /&gt;2022-09-22 14:03:38 Sep 22 14:03:38 ba-prod-web audisp-remote: queue is full - dropping event&lt;BR /&gt;2022-09-22 14:03:38 Sep 22 14:03:38 ba-prod-web systemd: Stopped Systemd service file for Splunk, generated by 'splunk enable boot-start'.&lt;BR /&gt;2022-09-22 14:03:38 Sep 22 14:03:38 ba-prod-web systemd: Stopping Systemd service file for Splunk, generated by 'splunk enable boot-start'...&lt;BR /&gt;2022-09-22 14:03:38 Sep 22 14:03:38 ba-prod-web splunk: Dying on signal #15 (si_code=0), sent by PID 1 (UID 0)&lt;BR /&gt;2022-09-22 14:03:38 Sep 22 14:03:38 ba-qa-web audisp-remote: queue is full - dropping event&lt;BR /&gt;2022-09-22 14:03:37 Sep 22 14:03:37 ba-qa-web audisp-remote: queue is full - dropping event&lt;BR /&gt;2022-09-22 14:03:36 Sep 22 14:03:36 ba-qa-web audisp-remote: queue is full - dropping event&lt;/P&gt;
&lt;P&gt;the last entry for the stanza that stopped working was:&lt;BR /&gt;2022-09-22 14:03:37 Sep 22 14:03:37 ba-qa-web audisp-remote: queue is full - dropping event&lt;/P&gt;
&lt;P&gt;all the other monitor an dscripted inputs are working on that server except for the one above.&lt;BR /&gt;the version of the forwarder is 7.2.3.&lt;BR /&gt;I am running other forwarders with this version that are indexing messages log entries and they are working as expected.&lt;BR /&gt;the stanza I used was a copy and paste from the Splunk_TA_nix add-on (except I removed the other log files and just used messages), so IMO this would be the bbest practices".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have a few questions:&lt;BR /&gt;1. why might be the reason why the stanza with "*' not work anymore while the one without it works?&lt;BR /&gt;2. Am I correct to believe that we do not need the stanza with "*", what are the consequences that I might not be aware of not using a stanza with "*"?&lt;BR /&gt;3. why would uid 1 (root) kill splunk (believe this is the reason why splunk stopped indexing messages log files again the 2nd time)?&lt;BR /&gt;4. any insights to understand this issue would be greatly apreciated. As far as i know right now, using my stanza should be good practice if we do not need the backup messages log files but I am concern I am missing something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 19:52:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputs-conf-not-indexing-var-log-messages/m-p/614348#M106313</guid>
      <dc:creator>alfredoh14</dc:creator>
      <dc:date>2022-09-23T19:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not indexing /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputs-conf-not-indexing-var-log-messages/m-p/614354#M106314</link>
      <description>&lt;P&gt;The most recent TA has inputs.conf like so for just for monitors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#Add-on upgrade 8.7 has new monitors.  Remark the old monitors and adding the current one.
[monitor:///Library/Logs]
disabled = 0
index = $someindex$

[monitor:///var/log]
whitelist=(\.log|log$|secure|messages|auth|mesg$|cron$|acpid$|\.out)
#customize aide.log$date$.gz file to excluded
blacklist=(aide.log-\d{8}.gz|anaconda\.syslog)
disabled = 0
index = $someindex$

[monitor:///var/adm]
whitelist=(\.log|log$|messages)
disabled = 0
index = $someindex$

[monitor:///etc]
whitelist=(\.conf|\.cfg|config$|\.ini|\.init|\.cf|\.cnf|shrc$|^ifcfg|\.profile|\.rc|\.rules|\.tab|tab$|\.login|policy$)
disabled = 0
index = $someindex$&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A1:&amp;nbsp; You just need to ingestion the current file not the pervious ones.&lt;BR /&gt;&lt;SPAN&gt;A2:&amp;nbsp; Using * is very wide net.&amp;nbsp; you should use a whitelist = $REX$&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A3. Work with Linux SA or look at the logs to figure out the cause of the kill.&amp;nbsp; Is a person or Job?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A4: I would recommend&amp;nbsp;what in the TA for messages&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 17:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputs-conf-not-indexing-var-log-messages/m-p/614354#M106314</guid>
      <dc:creator>youngsuh</dc:creator>
      <dc:date>2022-09-23T17:04:19Z</dc:date>
    </item>
  </channel>
</rss>

