<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mysterious Log Feed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Mysterious-Log-Feed/m-p/668056#M111981</link>
    <description>&lt;P&gt;I have a log feed which was configured by a previous employee. Documentation does not exist, of course...&lt;/P&gt;&lt;P&gt;The feed stopped once we migrated indexers. I checked the deployment server and there does not seem to be any apps on this server where the feed exists which ingest this feed.&lt;/P&gt;&lt;P&gt;Then, we added in the old indexer to the architecture and the feed started working again!&lt;/P&gt;&lt;P&gt;When I check these events in Search &amp;amp; Reporting, I can see the feed is only coming in via this legacy indexer by checking the splunk_server field.&lt;/P&gt;&lt;P&gt;I logged into the legacy indexer via CLI and used btool on inputs for the index, source and sourcetypes, no matches. Also struggling to find anything useful in the _internal events via search head GUI.&lt;/P&gt;&lt;P&gt;Both indexers are in a cluster and so the config should be identical, but the events only come in via the legacy indexer.&lt;/P&gt;&lt;P&gt;How can I find how this feed is configured?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 11:31:41 GMT</pubDate>
    <dc:creator>StuartMacL</dc:creator>
    <dc:date>2023-11-09T11:31:41Z</dc:date>
    <item>
      <title>Mysterious Log Feed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mysterious-Log-Feed/m-p/668056#M111981</link>
      <description>&lt;P&gt;I have a log feed which was configured by a previous employee. Documentation does not exist, of course...&lt;/P&gt;&lt;P&gt;The feed stopped once we migrated indexers. I checked the deployment server and there does not seem to be any apps on this server where the feed exists which ingest this feed.&lt;/P&gt;&lt;P&gt;Then, we added in the old indexer to the architecture and the feed started working again!&lt;/P&gt;&lt;P&gt;When I check these events in Search &amp;amp; Reporting, I can see the feed is only coming in via this legacy indexer by checking the splunk_server field.&lt;/P&gt;&lt;P&gt;I logged into the legacy indexer via CLI and used btool on inputs for the index, source and sourcetypes, no matches. Also struggling to find anything useful in the _internal events via search head GUI.&lt;/P&gt;&lt;P&gt;Both indexers are in a cluster and so the config should be identical, but the events only come in via the legacy indexer.&lt;/P&gt;&lt;P&gt;How can I find how this feed is configured?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 11:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mysterious-Log-Feed/m-p/668056#M111981</guid>
      <dc:creator>StuartMacL</dc:creator>
      <dc:date>2023-11-09T11:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mysterious Log Feed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mysterious-Log-Feed/m-p/668101#M111987</link>
      <description>&lt;P&gt;One or more of the forwarders are either not using the Deployment Server, are not in a serverclass in the DS, or have outputs.conf set in $SPLUNK_HOME/etc/system/local (which overrides settings from the DS).&amp;nbsp; The forwarder(s) still has the old indexer configured and is not getting the new indexer list from anywhere.&lt;/P&gt;&lt;P&gt;You'll have to sign in to the forwarders in question and repair them manually.&amp;nbsp; Move settings from $SPLUNK_HOME/etc/system/local to custom apps.&amp;nbsp; Ensure they are consulting the DS and are represented in a serverclass on the DS.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mysterious-Log-Feed/m-p/668101#M111987</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-09T15:35:17Z</dc:date>
    </item>
  </channel>
</rss>

