<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Ingest issues in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656698#M111203</link>
    <description>&lt;P&gt;Howdy Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working on my Splunk deployment and ran into a funky issue. I am ingesting Palo Alto FW and Meraki network device logs via syslog server. Rsyslog is set to write logs down to a file and the UF is set to monitor the directories.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No issues there, however I do run into an issue why I try to source type or set an index for these logs. I have edited the indexes.conf in the local folder on my cluster manager and pushed the required indexes to my indexers.&amp;nbsp; When I go to search for the logs on my search head I cannot find any data. However it works properly whenever i do not have sourcetyping and index destination in my inputs.conf.&lt;/P&gt;&lt;P&gt;Any idea as to why?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 15:42:59 GMT</pubDate>
    <dc:creator>ChristianF</dc:creator>
    <dc:date>2023-09-05T15:42:59Z</dc:date>
    <item>
      <title>Data Ingest issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656698#M111203</link>
      <description>&lt;P&gt;Howdy Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working on my Splunk deployment and ran into a funky issue. I am ingesting Palo Alto FW and Meraki network device logs via syslog server. Rsyslog is set to write logs down to a file and the UF is set to monitor the directories.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No issues there, however I do run into an issue why I try to source type or set an index for these logs. I have edited the indexes.conf in the local folder on my cluster manager and pushed the required indexes to my indexers.&amp;nbsp; When I go to search for the logs on my search head I cannot find any data. However it works properly whenever i do not have sourcetyping and index destination in my inputs.conf.&lt;/P&gt;&lt;P&gt;Any idea as to why?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 15:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656698#M111203</guid>
      <dc:creator>ChristianF</dc:creator>
      <dc:date>2023-09-05T15:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingest issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656723#M111208</link>
      <description>&lt;P&gt;We need more info. Especially relevant configs.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 20:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656723#M111208</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-05T20:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingest issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656730#M111215</link>
      <description>&lt;P&gt;Are you monitoring the path where the logs are written in the UF.&lt;/P&gt;&lt;P&gt;can you share your inputs.conf ? this will help you check further.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 21:05:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656730#M111215</guid>
      <dc:creator>Manojbh_splunk</dc:creator>
      <dc:date>2023-09-05T21:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingest issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656824#M111230</link>
      <description>&lt;P&gt;I actually ended up resolving the issue myself, I didn't have my indexes.conf file on my search head which didn't allow me to see the data on my cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 12:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656824#M111230</guid>
      <dc:creator>ChristianF</dc:creator>
      <dc:date>2023-09-06T12:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingest issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656863#M111234</link>
      <description>&lt;P&gt;Lack of indexes.conf on SH results only in lack of auto-completion in the search edit window. You still can manually write which index you want to search and it works.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 15:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingest-issues/m-p/656863#M111234</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-06T15:52:31Z</dc:date>
    </item>
  </channel>
</rss>

