<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexers not parsing events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627887#M107752</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252255"&gt;@devin07&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you logs in XML or raw?&lt;/P&gt;&lt;P&gt;try using&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;renderxml=false&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sat, 21 Jan 2023 17:24:00 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-01-21T17:24:00Z</dc:date>
    <item>
      <title>Why are indexers not parsing events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627877#M107746</link>
      <description>&lt;P&gt;Fairly new to Splunk so may not have the correct terms for everything. Currently working in a distributed environment with Splunk Enterprise with windows and Linux host. These hosts are sending logs via UFs to the clustered indexers. There is also an HF that is receiving logs from apps and AWS. My issue is that the logs coming from my UF are not being parsed into field name-value pairs. The windows/Linux host, indexers, and Search Heads all have the splunk_TA_nix and splunk_TA_windows add-ons installed. &amp;nbsp;I almost feel like my indexers are not parsing the data that is coming in.&lt;/P&gt;
&lt;P&gt;Log data is getting into Splunk and I can see my events however it is all in a format similar to this, very crude I know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;data&amp;gt;&amp;lt;data&amp;gt;&amp;lt;data&amp;gt;1039&amp;lt;data&amp;gt;&amp;lt;data&amp;gt;&amp;lt;data&amp;gt;time&amp;lt;data&amp;gt;&amp;lt;data&amp;gt;program&amp;lt;data&amp;gt;splunk&amp;lt;data&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like it to be in field name values. &amp;nbsp;At some point I was receiving logs in this format however I am no longer. What could be causing this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;time: 10:39
program: splunk&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 17:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627877#M107746</guid>
      <dc:creator>devin07</dc:creator>
      <dc:date>2023-01-23T17:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627879#M107747</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252255"&gt;@devin07&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;one question: do logs from UFs pass throgh the HF?&lt;/P&gt;&lt;P&gt;if yes, you have to install windows and linux TA also on HF.&lt;/P&gt;&lt;P&gt;I suppose that you are using the Linux and windows TAs also on UFs to input data, is it correct?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 16:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627879#M107747</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-21T16:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627882#M107748</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Thanks for responding, so no the UFs do not send logs to the HF in our env. The UFs send logs straight to the indexers. We are using the HF for AWS cloud trail/cloudwatch logs and for some applications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Linux and windows TAs on the UF are used to input data, yes. &amp;nbsp;Data is getting into Splunk fine, it's just not being parsed it seems if that makes since&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 16:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627882#M107748</guid>
      <dc:creator>devin07</dc:creator>
      <dc:date>2023-01-21T16:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627884#M107749</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252255"&gt;@devin07&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you're using the same TA both on UFs and IDXs, if not check the sourcetype assigned on UFs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 16:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627884#M107749</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-21T16:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627885#M107750</link>
      <description>&lt;P&gt;Same source type, I used a DS to deploy the TA and just checked the source types are the same&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 17:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627885#M107750</guid>
      <dc:creator>devin07</dc:creator>
      <dc:date>2023-01-21T17:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627886#M107751</link>
      <description>&lt;P&gt;Not sure if this helps I was looking further and under index=windeventlog I am only seeing a source type of XmlWinEventLog and not just a source type of WinEventLog our inputs.conf does have renderxml=true. So if it helps it is looking like the XmlWinEventLog source types are not being parsed correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could it be that my fields are being extracted automatically?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 17:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627886#M107751</guid>
      <dc:creator>devin07</dc:creator>
      <dc:date>2023-01-21T17:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627887#M107752</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252255"&gt;@devin07&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you logs in XML or raw?&lt;/P&gt;&lt;P&gt;try using&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;renderxml=false&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 17:24:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627887#M107752</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-21T17:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627890#M107753</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;This was it, we had used a file that had this set to true rather than false thank you!!!&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 19:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627890#M107753</guid>
      <dc:creator>devin07</dc:creator>
      <dc:date>2023-01-21T19:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers not parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627900#M107754</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252255"&gt;@devin07&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 07:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexers-not-parsing-events/m-p/627900#M107754</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-22T07:09:22Z</dc:date>
    </item>
  </channel>
</rss>

