<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs for ESX going into two different indexes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711268#M117505</link>
    <description>&lt;P&gt;I have ESX hosts sending logs to rsyslog and then being ingested in Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Originally, I configured to ingest all logs (my linux servers and ESX) into one index called linux. Later, I created new index called "esx" and modified the inputs.conf on my rsyslog server to reflect in stanzas for all the esx hosts and esxvcenter (added index = esx) and restarted Splunkforwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it looks like, I am getting data in both indexes, linux and esx.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked all possible inputs.conf on my rsyslog server but can't find anywhere that directs ESX logs to "linux" index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help to troubleshoot the issue would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 13:35:40 GMT</pubDate>
    <dc:creator>jkamdar</dc:creator>
    <dc:date>2025-02-11T13:35:40Z</dc:date>
    <item>
      <title>Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711268#M117505</link>
      <description>&lt;P&gt;I have ESX hosts sending logs to rsyslog and then being ingested in Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Originally, I configured to ingest all logs (my linux servers and ESX) into one index called linux. Later, I created new index called "esx" and modified the inputs.conf on my rsyslog server to reflect in stanzas for all the esx hosts and esxvcenter (added index = esx) and restarted Splunkforwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it looks like, I am getting data in both indexes, linux and esx.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked all possible inputs.conf on my rsyslog server but can't find anywhere that directs ESX logs to "linux" index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help to troubleshoot the issue would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 13:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711268#M117505</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-02-11T13:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711270#M117506</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first, are you sure that you are analyzing only the new data and not also the oldest?&lt;/P&gt;&lt;P&gt;Anyway, use btool (&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Troubleshooting/Usebtooltotroubleshootconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&amp;nbsp;) to debug your configurations because, probably there's another input.&lt;/P&gt;&lt;P&gt;At least, are you sure that you're receiving logs from the same host?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 13:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711270#M117506</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-11T13:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711271#M117507</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;thanks for a quick response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;at first, are you sure that you are analyzing only the new data and not also the oldest?&lt;/P&gt;&lt;P&gt;Yes, I have changes time picker for last 15 or 60 minutes to make sure it's all recent data&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;nbsp;At least, are you sure that you're receiving logs from the same host?&lt;/P&gt;&lt;P&gt;Yes,&amp;nbsp; this is a very small deployment and have only one ESX server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&lt;SPAN&gt;Anyway, use btool&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I meant try btool but ended up posting question before I try that. I will do that now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711271#M117507</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-02-11T14:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711293#M117511</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried btool commands on my rsyslog server:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;splunk btool inputs list&lt;/EM&gt;&lt;/STRONG&gt; and&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;splunk btool inputs list --debug | grep index&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and the files I found are configured properly.&amp;nbsp; Not sure where to look next.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:48:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711293#M117511</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-02-11T16:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711294#M117512</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's really difficoult to debug your issue without accessing your conf files and your data!&lt;/P&gt;&lt;P&gt;could you share your inputs.conf and props.conf?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711294#M117512</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-11T16:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711295#M117513</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you send the inputs.conf and props.conf files? Also, please use the btool command to check if there are any duplicate inputs.conf configurations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To check for duplicate inputs.conf configurations using the btool command, you can run the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;/opt/splunk/bin/splunk btool inputs list --debug&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;This command will display the full path to each inputs.conf file that Splunk is reading from, making it easier to identify any duplicates.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 17:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711295#M117513</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-11T17:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711304#M117517</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp; thanks for your help but unfortunately, I can't share any files, sorry. I am in a air-gapped environment. I have already run &lt;EM&gt;&lt;STRONG&gt;splunk btool inputs list --debug | grep index&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;. but I will try without using "grep index" and see if I can find anything weird. I haven't checked props.conf but I will check it now. As far as I know, I haven't made any change in the props.conf.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 19:17:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711304#M117517</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-02-11T19:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711337#M117524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;cases as your is usually caused by a misconfiguration, for this reason I hint to better analyze your btool result, not using grep,&lt;/P&gt;&lt;P&gt;The issue could be caused by two inputs or by a transformation in props.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 07:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711337#M117524</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-12T07:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Logs for ESX going into two different indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711415#M117530</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I never got a chance to do it today but will try tomorrow and report back.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 21:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-for-ESX-going-into-two-different-indexes/m-p/711415#M117530</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-02-12T21:03:35Z</dc:date>
    </item>
  </channel>
</rss>

