<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs not coming to splunk from UF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648830#M110276</link>
    <description>&lt;P&gt;This is interesting since the license warning says about 5 violations during 30-day period which is the typical setting for a Splunk Free instance. Your environment seems much bigger than the one for Splunk Free instance.&lt;/P&gt;&lt;P&gt;There is probably more things wrong underneath.&lt;/P&gt;&lt;P&gt;We don't know your event routing, we don't know your architecture, we don't know your search settings.&lt;/P&gt;&lt;P&gt;I'd advise you get a consultant to look over your environment because it looks as if you have more problems than just events which are supposedly not showing in search (but they might be although they might be wrongly parsed and misplaced, for example).&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 16:53:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-06-30T16:53:13Z</dc:date>
    <item>
      <title>Logs not coming to splunk from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648798#M110269</link>
      <description>&lt;P&gt;Hi team,&lt;BR /&gt;&lt;BR /&gt;Logs are not coming to splunk .The UF is working fine and even connected to indexers, inputs.conf and everything seems perfect.&lt;BR /&gt;we are facing this issue for few UFs only.&lt;BR /&gt;can you suggest something which i should check?&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the warnings we are getting :-&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;1. Search peer dallpspiap090m has the following message: Daily indexing volume limit exceeded. Per the Splunk Enterprise license policy in effect, search is disabled after 5 warnings over a 30-day window. Your Splunk deployment is subject to license enforcement. See&lt;SPAN&gt;&amp;nbsp;&lt;A href="https://splunkusle.vtitel.net/en-US/manager/search/licenseusage" target="_blank" rel="noopener"&gt;License Manager&lt;SPAN&gt;&amp;nbsp;for details.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;STRONG&gt;2. Root Cause(s):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Sum of 3 highest per-cpu iowaits reached red threshold of 15&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Sum of 3 highest per-cpu iowaits reached yellow threshold of 7&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;Maximum per-cpu iowait reached red threshold of 10&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;STRONG&gt;&lt;STRONG&gt;Unhealthy Instances:&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;dallpshdap010m&lt;/LI&gt;&lt;LI&gt;mialvshdap010m.vtitel.net&lt;/LI&gt;&lt;LI&gt;dallvissap010m.vtitel.net&lt;/LI&gt;&lt;LI&gt;mialvissap030m.vtitel.net&lt;/LI&gt;&lt;LI&gt;dallvissap030m.vtitel.net&lt;/LI&gt;&lt;LI&gt;mialvissap010m.vtitel.net&lt;/LI&gt;&lt;LI&gt;dallvissap020m.vtitel.net&lt;/LI&gt;&lt;LI&gt;mialvissap020m.vtitel.net&lt;H3&gt;&lt;SPAN&gt;&amp;nbsp;3.&amp;nbsp;&lt;SPAN&gt;Search Lag&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Root Cause(s):&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;The percentage of non high priority searches lagged (67%) over the last 24 hours is very high and exceeded the yellow thresholds (40%) on this Splunk instance. Total Searches that were part of this percentage=268303. Total lagged Searches=182113&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 30 Jun 2023 11:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648798#M110269</guid>
      <dc:creator>Hemant93</dc:creator>
      <dc:date>2023-06-30T11:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming to splunk from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648802#M110270</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;your logs are coming to splunk, but you cannot search those as you are ingested too many times over your license quota.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; Search peer dallpspiap090m has the following message: Daily indexing volume limit exceeded. Per the Splunk Enterprise license policy in effect, search is disabled after 5 warnings over a 30-day window. Your Splunk deployment is subject to license enforcement. See License Manager for details.&lt;/LI-CODE&gt;&lt;P&gt;You need to order Unlock license from Splunk. Contact to your account team and ask this.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 11:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648802#M110270</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-30T11:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming to splunk from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648803#M110271</link>
      <description>&lt;P&gt;Hi Isoutamo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we are getting for most of the servers but not getting logs for recently configured servers.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 12:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648803#M110271</guid>
      <dc:creator>Hemant93</dc:creator>
      <dc:date>2023-06-30T12:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming to splunk from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648830#M110276</link>
      <description>&lt;P&gt;This is interesting since the license warning says about 5 violations during 30-day period which is the typical setting for a Splunk Free instance. Your environment seems much bigger than the one for Splunk Free instance.&lt;/P&gt;&lt;P&gt;There is probably more things wrong underneath.&lt;/P&gt;&lt;P&gt;We don't know your event routing, we don't know your architecture, we don't know your search settings.&lt;/P&gt;&lt;P&gt;I'd advise you get a consultant to look over your environment because it looks as if you have more problems than just events which are supposedly not showing in search (but they might be although they might be wrongly parsed and misplaced, for example).&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 16:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648830#M110276</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-30T16:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not coming to splunk from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648835#M110277</link>
      <description>&lt;P&gt;Definitely there seems to be something else too. 5/30 was normal limit with older 7&amp;amp;8 versions, not only free. If your instance is using free license then you cannot get unlock license. That’s just for paid customers!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 18:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-not-coming-to-splunk-from-UF/m-p/648835#M110277</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-30T18:39:25Z</dc:date>
    </item>
  </channel>
</rss>

