<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs are not forwarded to splunk from splunk forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-forwarded-to-splunk-from-splunk-forwarder/m-p/658312#M111364</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259965"&gt;@muqeeiz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, but I don't see any error in the messages you shared!&lt;/P&gt;&lt;P&gt;anyway, check the permissions on the files to read.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 15:18:16 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-09-21T15:18:16Z</dc:date>
    <item>
      <title>Logs are not forwarded to splunk from splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-forwarded-to-splunk-from-splunk-forwarder/m-p/658309#M111363</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;my logs do not appear in the index and in splunkd.log i get the following error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;09-21-2023 16:36:40.693 +0200 INFO  AutoLoadBalancedConnectionStrategy [7698 TcpOutEloop] - Connected to idx=xx.xx.xx.xx:16313, pset=0, reuse=0. using ACK.
09-21-2023 16:36:48.003 +0200 INFO  TailReader [7705 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'
09-21-2023 16:37:10.613 +0200 INFO  AutoLoadBalancedConnectionStrategy [7698 TcpOutEloop] - Connected to idx=xx.xx.xx.xx:16313, pset=0, reuse=0. using ACK.
09-21-2023 16:37:18.002 +0200 INFO  TailReader [7705 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my inputs.conf has only the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[default]
host = myhostname
index = vcenter-index-name
[monitor:///var/log/remotelogs/vcenter-rep/analytics.log]
sourcetype =  "vcenter"
queueSize = 50MB
crcSalt = &amp;lt;SOURCE&amp;gt;
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would mention that I have the same configuration on a different server and logs end out in splunk without a problem and this error does not appear on the other servers:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;09-21-2023 16:37:18.002 +0200 INFO  TailReader [7705 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 15:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-forwarded-to-splunk-from-splunk-forwarder/m-p/658309#M111363</guid>
      <dc:creator>muqeeiz</dc:creator>
      <dc:date>2023-09-21T15:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not forwarded to splunk from splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-forwarded-to-splunk-from-splunk-forwarder/m-p/658312#M111364</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259965"&gt;@muqeeiz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, but I don't see any error in the messages you shared!&lt;/P&gt;&lt;P&gt;anyway, check the permissions on the files to read.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 15:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-forwarded-to-splunk-from-splunk-forwarder/m-p/658312#M111364</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-21T15:18:16Z</dc:date>
    </item>
  </channel>
</rss>

