<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog stopped sending logs to Indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647328#M110081</link>
    <description>&lt;P&gt;This also applies to my rsa logs, which stopped sending logs 7 days ago.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 15:48:24 GMT</pubDate>
    <dc:creator>Lwoods</dc:creator>
    <dc:date>2023-06-16T15:48:24Z</dc:date>
    <item>
      <title>Why did syslog stopped sending logs to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647322#M110078</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a syslog server that collects logs from various hosts, (esxi).&amp;nbsp; The syslog is currently receiving the logs each day from the hosts and puts them the&amp;nbsp; "data/ES/" directory.&amp;nbsp; I have splunkforwarder installed the syslog and inside the splunkforwarder, I have the esxi add-on app.&lt;/P&gt;
&lt;P&gt;Inside the esxi add-on app&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created an input stanza that monitors the data and sent to the indexer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[monitor:///data/ES/]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = vmware-esxilog&lt;BR /&gt;sourcetype = vmw-syslog&lt;/P&gt;
&lt;P&gt;The logs stopped sending to the indexer several days ago.&amp;nbsp; However, my firewall logs are still sending to the indexer.&amp;nbsp; The firewall logs are sent the same directory "/data/fire/" and then sent to index.&amp;nbsp; What am I missing?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 16:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647322#M110078</guid>
      <dc:creator>Lwoods</dc:creator>
      <dc:date>2023-06-22T16:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647323#M110079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253971"&gt;@Lwoods&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;obvious question: there was change in your firewall routes or configurations in the last days?&lt;/P&gt;&lt;P&gt;In general I always put a file indication in the stanza header, e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///data/ES/*]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Are there logs after the 1st of June or logs stopped to arrive with the end of May?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 15:37:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647323#M110079</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-16T15:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647325#M110080</link>
      <description>&lt;P&gt;The logs stopped sending yesterday.&amp;nbsp; Firewall logs are still sending&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you put a wildcard inside the monitor stanza&amp;nbsp; like this:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[monitor:///data/ES/*]&lt;/PRE&gt;</description>
      <pubDate>Fri, 16 Jun 2023 15:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647325#M110080</guid>
      <dc:creator>Lwoods</dc:creator>
      <dc:date>2023-06-16T15:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647328#M110081</link>
      <description>&lt;P&gt;This also applies to my rsa logs, which stopped sending logs 7 days ago.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 15:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647328#M110081</guid>
      <dc:creator>Lwoods</dc:creator>
      <dc:date>2023-06-16T15:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647612#M110126</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall logs are still sending logs to syslog, and syslog is forwarding them up to the indexer.&amp;nbsp; &amp;nbsp;Esxi and other devices have stopped reporting 12 days ago.&amp;nbsp; 8 June.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 13:45:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647612#M110126</guid>
      <dc:creator>Lwoods</dc:creator>
      <dc:date>2023-06-20T13:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647877#M110162</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253971"&gt;@Lwoods&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if the Forwarder is sending other logs and your configuration worked since few days ago, the easiest solution is that something changed in the intermediate channel: esxi syslog configuration or firewall routes.&lt;/P&gt;&lt;P&gt;I suppose that you already checked them, is it correct?&lt;/P&gt;&lt;P&gt;if you're using tcp as protocol check using telnet the connection between esxi and HF.&lt;/P&gt;&lt;P&gt;then check the traffic through the intermediate firewall and see, using tcpdump, if your HF is receiving from your esxi on your protocol and your port.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 06:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647877#M110162</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-22T06:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog stopped sending logs to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647898#M110168</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response.&amp;nbsp; &amp;nbsp;The esxi logs add-on installed on the deployment app, didn't match what was on the syslog.&amp;nbsp; All the deployment apps are pushed down to the syslog.&amp;nbsp; When configuring inputs.conf (monitor stanza) I didn't mirror those settings in the deployment server.&amp;nbsp; Once I fixed it, it worked.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all you help and expertise..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy Splunking&lt;/P&gt;&lt;P&gt;Lisa&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 11:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-syslog-stopped-sending-logs-to-indexer/m-p/647898#M110168</guid>
      <dc:creator>Lwoods</dc:creator>
      <dc:date>2023-06-22T11:23:20Z</dc:date>
    </item>
  </channel>
</rss>

