<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs are not getting from Linux machine in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/696598#M115598</link>
    <description>&lt;P&gt;This thread is more than 2 years old.&amp;nbsp; For better chances at having more people see it, please post a new question.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Aug 2024 20:59:29 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-17T20:59:29Z</dc:date>
    <item>
      <title>Why are logs not getting in from Linux machine?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603745#M105041</link>
      <description>&lt;P&gt;Logs are not getting in from Linux machine&lt;/P&gt;
&lt;P&gt;I am using Splunk cloud trial and in a Linux machine and installed universal forwarder and added&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;monitor path as well. But no luck.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 20:48:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603745#M105041</guid>
      <dc:creator>an</dc:creator>
      <dc:date>2022-06-29T20:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603787#M105042</link>
      <description>&lt;P&gt;Did you install the Universal Forwarder app from your cloud SH on the UF?&amp;nbsp; Did you then restart the UF?&lt;/P&gt;&lt;P&gt;Have you checked the UF's logs to see if any messages might explain why it's unable to send to Splunk Cloud?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 14:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603787#M105042</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-29T14:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603788#M105043</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247295"&gt;@an&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You could do the following to troubleshoot this issue:&lt;BR /&gt;&lt;BR /&gt;1 - Download the Universal Forwarder app from your Splunk Cloud trial instance and install it on /opt/splunkforwarder/etc/apps (If you not already installed this app).&lt;/P&gt;&lt;P&gt;2 - Verify the permissions of the files that you added on the monitor path (if the user that is running Splunk can read/execute these files).&lt;/P&gt;&lt;P&gt;3 - Verify if the monitor configs are correct and an index is being defined on the monitor stanza.&lt;/P&gt;&lt;P&gt;4 - Run &lt;STRONG&gt;splunk btool check&lt;/STRONG&gt; command to check for any typos on .conf files.&lt;/P&gt;&lt;P&gt;5 - Restart the Universal Forwarder (The changes on the Universal Forwarder are only applied after a restart).&lt;/P&gt;&lt;P&gt;6 - Search for &lt;STRONG&gt;index=_internal host=&amp;lt;your_uf_host&amp;gt;&lt;/STRONG&gt; on Splunk Cloud trial to verify if internal logs are being indexed.&lt;SPAN&gt;&amp;nbsp;If the internal logs are being indexed, search for the index that you configured your monitor on the step 3.&lt;BR /&gt;6.1 - If there are internal logs from your instance but there are no logs on your index, there is an error on the configs of this input.&lt;BR /&gt;6.2 - If there are no internal logs, the error could be related to a firewall issue that you could try to troubleshoot on the UF log files (search for an error that shows that you cannot connect to the Splunk Cloud):&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;cat /opt/splunkforwarder/var/log/splunk/splunkd.log | grep -i ERROR&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 14:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603788#M105043</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2022-06-29T14:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603836#M105044</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-29 at 11.01.01 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20356iDAADFB1F3CEF7875/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-06-29 at 11.01.01 PM.png" alt="Screenshot 2022-06-29 at 11.01.01 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-29 at 11.03.22 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20355i4CD74F219DF1699D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-06-29 at 11.03.22 PM.png" alt="Screenshot 2022-06-29 at 11.03.22 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-29 at 11.04.05 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20354iAAF6A489FBA28D2E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-06-29 at 11.04.05 PM.png" alt="Screenshot 2022-06-29 at 11.04.05 PM.png" /&gt;&lt;/span&gt;this is getting if i am running&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cat /opt/splunkforwarder/var/log/splunk/splunkd.log | grep -i ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and copied input and output config&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 17:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603836#M105044</guid>
      <dc:creator>an</dc:creator>
      <dc:date>2022-06-29T17:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603837#M105045</link>
      <description>&lt;P&gt;yes installed&amp;nbsp;&lt;SPAN&gt;Universal Forwarder and restarted&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 17:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603837#M105045</guid>
      <dc:creator>an</dc:creator>
      <dc:date>2022-06-29T17:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603855#M105046</link>
      <description>&lt;P&gt;Double-check your firewalls to make sure they allow connections from the UF to Splunk Cloud.&lt;/P&gt;&lt;P&gt;The outputs.conf file doesn't look right.&amp;nbsp; There should be a certificate specified, but I don't see it.&amp;nbsp; Are you sure this is the outputs.conf that came with the 100_splunkclouduf app?&lt;/P&gt;&lt;P&gt;It's not necessary to specify &lt;FONT face="courier new,courier"&gt;source&lt;/FONT&gt; in a monitor clause.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;source&lt;/FONT&gt; field is populated automatically from the monitored file name.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 19:45:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603855#M105046</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-29T19:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603857#M105047</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;When you are using Splunk Cloud then outputs.conf must contain TLS certs. It seems that you haven't those on your outputs.conf. Should be something like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup = SC_STACK
useACK = true

[tcpout:SC_STACK]
server = inputs1.SC_STACK.splunkcloud.com:9997, inputs2.SC_STACK.splunkcloud.com:9997, ..... inputs15.SC_STACK.splunkcloud.com:9997
compressed = false

clientCert = $SPLUNK_HOME/etc/apps/100_SC_STACK_splunkcloud/default/SC_STACK_server.pem

sslCommonNameToCheck = *.SC_STACK.splunkcloud.com
sslVerifyServerCert = true
useClientSSLCompression = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could download a new valid UF connection package from your SC instance. Just select App "Universal Forwarder" on left side panel and follow it's instructions.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 20:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/603857#M105047</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-29T20:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not getting in from Linux machine?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/604258#M105100</link>
      <description>&lt;P&gt;Problem solved, by reinstalling the UF. Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 06:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/604258#M105100</guid>
      <dc:creator>an</dc:creator>
      <dc:date>2022-07-03T06:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/696592#M115595</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;I am facing the same issue getting windows logs and sysmon logs but not getting any Linux and zeek logs . Using this inputs.conf file and all settings followed per documentation credneial package installed sucessfully as well. Also installed Zeek Apps as well. Sorry forgot to mention that seeing hosts when do index=_internal search last 24 hours.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help please ?&lt;/P&gt;&lt;P&gt;default]&lt;BR /&gt;host = zeek-VirtualBox&lt;/P&gt;&lt;P&gt;[monitor:///var/log/messages]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = unix&lt;/P&gt;&lt;P&gt;[monitor:///var/log/syslog]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = unix&lt;/P&gt;&lt;P&gt;[monitor:///var/log/faillog]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = unix&lt;/P&gt;&lt;P&gt;[monitor:///var/log/auth.log]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = unix&lt;/P&gt;&lt;P&gt;[monitor:///opt/zeek/log/current]&lt;BR /&gt;disabled = 0&lt;BR /&gt;_TCP_ROUTING = *&lt;BR /&gt;index = zeek&lt;BR /&gt;sourcetype = bro:jason&lt;BR /&gt;whitelist = \.log$&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 17:21:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/696592#M115595</guid>
      <dc:creator>sidnakvee</dc:creator>
      <dc:date>2024-08-17T17:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: logs are not getting from Linux machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/696598#M115598</link>
      <description>&lt;P&gt;This thread is more than 2 years old.&amp;nbsp; For better chances at having more people see it, please post a new question.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 20:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-getting-in-from-Linux-machine/m-p/696598#M115598</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-17T20:59:29Z</dc:date>
    </item>
  </channel>
</rss>

