<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs are not getting indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688154#M114615</link>
    <description>&lt;P&gt;Please share the inputs.conf and props.conf stanzas related to the input.&lt;/P&gt;&lt;P&gt;Have you searched the last chance index (usually 'main')?&amp;nbsp; Have you searched all time, including the future, in case the timestamps are not interpreted correctly?&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2024 12:21:24 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-05-21T12:21:24Z</dc:date>
    <item>
      <title>Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688068#M114604</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;Recently, I am trying to ingest the logs from my server. But it is not getting indexed. The log file which I am trying to ingest has different timestamp with same events.&lt;/P&gt;
&lt;P&gt;Events in log file:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;1712744099:{"jsonefd":"1.0","result":"1357","id":1}
1712744400:{"jsonefd":"1.0","result":"1357","id":1}
1712745680:{"jsonefd":"1.0","result":"1357","id":1}
1714518017:{"jsonefd":"1.0","result":"1378","id":1}
1715299221:{"jsonefd":"1.0","result":"1366","id":1}&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I tried with crcsalt but still no luck. Kindly help if anyone faced this issue before.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to ingest the events even the events are same with different timestamps.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 20:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688068#M114604</guid>
      <dc:creator>gowthammahes</dc:creator>
      <dc:date>2024-05-20T20:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688078#M114606</link>
      <description>&lt;P&gt;Help us help you by providing more information.&lt;/P&gt;&lt;P&gt;How is the data being onboarded?&amp;nbsp; IOW, what is the method for getting the events to Splunk?&lt;/P&gt;&lt;P&gt;Are there any errors in the logs?&lt;/P&gt;&lt;P&gt;How have you determined the events are not indexed?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 20:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688078#M114606</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-20T20:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688097#M114609</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248853"&gt;@gowthammahes&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to index this log file in indexer/search head directly&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;are you trying to read this file thru Universal Forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 01:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688097#M114609</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-05-21T01:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688127#M114613</link>
      <description>&lt;P&gt;We have installed the universal forwarder and the events are forwarded to intermediate forwarder from the splunk uf and then it sent to indexer.&lt;/P&gt;&lt;P&gt;But i could the host internal logs are being ingested into splunk. Only the file is not getting monitored&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 08:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688127#M114613</guid>
      <dc:creator>gowthammahes</dc:creator>
      <dc:date>2024-05-21T08:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688128#M114614</link>
      <description>&lt;P&gt;How is the data being onboarded?&amp;nbsp; IOW, what is the method for getting the events to Splunk?&lt;/P&gt;&lt;P&gt;-- Have installed the universal forwarder and added monitor stanza in it. and then uf will send the logs to intermediate fwd and then to indexer&lt;/P&gt;&lt;P&gt;Are there any errors in the logs?&lt;/P&gt;&lt;P&gt;There is no error even in debug mode&lt;/P&gt;&lt;P&gt;How have you determined the events are not indexed?&lt;/P&gt;&lt;P&gt;The index newly created and there is no events found in it.&amp;nbsp; Have verified the log event timestamp and searched the events in search head at same time&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 08:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688128#M114614</guid>
      <dc:creator>gowthammahes</dc:creator>
      <dc:date>2024-05-21T08:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688154#M114615</link>
      <description>&lt;P&gt;Please share the inputs.conf and props.conf stanzas related to the input.&lt;/P&gt;&lt;P&gt;Have you searched the last chance index (usually 'main')?&amp;nbsp; Have you searched all time, including the future, in case the timestamps are not interpreted correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 12:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688154#M114615</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-21T12:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688160#M114616</link>
      <description>&lt;P&gt;&lt;STRONG&gt;inputs.conf:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;[monitor:///var/log/json]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = app_prod&lt;BR /&gt;sourcetype = app-json&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;
&lt;P&gt;there is&lt;STRONG&gt; no props.conf&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;events:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;1712744099:{"jsonefd":"1.0","result":"1357","id":1}
1712744400:{"jsonefd":"1.0","result":"1357","id":1}
1712745680:{"jsonefd":"1.0","result":"1357","id":1}
1714518017:{"jsonefd":"1.0","result":"1378","id":1}
1715299221:{"jsonefd":"1.0","result":"1366","id":1}&lt;/LI-CODE&gt;
&lt;P&gt;As you said i searched with all time and no results found.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 18:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688160#M114616</guid>
      <dc:creator>gowthammahes</dc:creator>
      <dc:date>2024-05-21T18:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688174#M114618</link>
      <description>&lt;P&gt;Missing props could be a problem.&amp;nbsp; Try these settings.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[app:json]
TIME_PREFIX = ^
TIME_FORMAT = %s
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = FALSE
MAX_TIMESTAMP_LOOKAHEAD = 10
TRUNCATE = 10000
EVENT_BREAKER_ENABLE = TRUE
EVENT_BREAKER = ([\r\n]+)&lt;/LI-CODE&gt;&lt;P&gt;Note the change in sourcetype name.&amp;nbsp; Avoid using hyphens in identifiers since they could be mistaken for the subtraction operator.&lt;/P&gt;&lt;P&gt;By default, Splunk will not search future times so it won't detect timestamps that were misinterpreted in that direction.&amp;nbsp; Try &lt;FONT face="courier new,courier"&gt;index=app_prod earliest=-1y latest=+1y&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688174#M114618</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-21T14:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688848#M114688</link>
      <description>&lt;P&gt;The issue has been resolved. Actually there was two tcp out indexer groups caused the issue. Adding _tcp_routing fixed the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 08:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-not-getting-indexed/m-p/688848#M114688</guid>
      <dc:creator>gowthammahes</dc:creator>
      <dc:date>2024-05-28T08:49:47Z</dc:date>
    </item>
  </channel>
</rss>

