<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logdata not arriving from all Universal Forwarders in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762619#M120741</link>
    <description>&lt;P&gt;1.&amp;nbsp; group=tcpin_connection sourceIp=10.1.1.2&lt;BR /&gt;&lt;BR /&gt;2. The intermediat HF is set to just recive and send, not doing any routing or filtering.&lt;BR /&gt;&lt;BR /&gt;Indexer is neither set to&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2026 10:58:52 GMT</pubDate>
    <dc:creator>erikwie</dc:creator>
    <dc:date>2026-07-30T10:58:52Z</dc:date>
    <item>
      <title>Logdata not arriving from all Universal Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762613#M120736</link>
      <description>&lt;P&gt;Enviroment:&lt;BR /&gt;Distributed Splunk Enterprise 9.4.x running on Linux&amp;nbsp;&lt;BR /&gt;UFs sends data to 2 HFs S2S loadbalansing&lt;BR /&gt;HF sends logs to a single indexer&lt;BR /&gt;&lt;BR /&gt;Problem case:&lt;BR /&gt;2 servers on a vlan, lets say 10.1.1.2 and 10.1.1.3, one windows and one linux&lt;BR /&gt;Windows server sende logs and data in ingested and indexed, all is fine.&lt;BR /&gt;Linux server has nothing in indexes, and nothing in _internal index either&lt;BR /&gt;&lt;BR /&gt;I can see traffic in the firewall from UF to HF beeing allowed.&lt;BR /&gt;I can see _internal logs from metrics.log on both HFs that they du get data from both linux and windows servers&lt;BR /&gt;&lt;BR /&gt;I can not find any errors in any splunk logs&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can anyone please help me to figure out why I do not get any logs from the linux server while i du get from the Windows server?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 09:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762613#M120736</guid>
      <dc:creator>erikwie</dc:creator>
      <dc:date>2026-07-30T09:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logdata not arriving from all Universal Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762614#M120737</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/81640"&gt;@erikwie&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you using the Splunk_TA_nix add-on to ingest these logs?&lt;/P&gt;&lt;P&gt;did you enabled inputs on this add-on (by default they are all disabled)?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762614#M120737</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-07-30T10:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Logdata not arriving from all Universal Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762617#M120739</link>
      <description>&lt;P&gt;Hmm... that sounds a bit strange. Typically if you don't get internal logs that would mean that you have conmectivity problems somewhere along the way. But you're saying that:&lt;/P&gt;&lt;P&gt;1. Metrics show that data _is_ actually being delivered to HFs (which metrics did you check?)&lt;/P&gt;&lt;P&gt;2. The data is not properly forwarded and indexed on the indexer.&lt;/P&gt;&lt;P&gt;That would mean that either your HFs (or the indexer itself) do perform some sort of selective routing/filtering (you'd have to check your config for that but I find it unlikely) or the data _is_ actually delivered and indexed but you cannot find it (wrong metadata? Time/timezone problems? Search-time filters?).&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762617#M120739</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-30T10:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Logdata not arriving from all Universal Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762618#M120740</link>
      <description>&lt;P&gt;Not actually relevent to the problem, but yes&lt;BR /&gt;&lt;BR /&gt;I do not get the splunk internal logs to the _internal index (nor any other data)&lt;BR /&gt;The HF logs tells me there is about 430kb of data pr hour pr HF that comes from the 10.1.1.2 UF (linux) and is forwarded.&lt;BR /&gt;&lt;BR /&gt;This means that the outputs.conf is present and correct on the UF.&lt;BR /&gt;Conf is deplyed with deployment manager, so same on all linux hosts, problem is not on all linux hosts, but atleast 2 so far.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762618#M120740</guid>
      <dc:creator>erikwie</dc:creator>
      <dc:date>2026-07-30T10:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Logdata not arriving from all Universal Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762619#M120741</link>
      <description>&lt;P&gt;1.&amp;nbsp; group=tcpin_connection sourceIp=10.1.1.2&lt;BR /&gt;&lt;BR /&gt;2. The intermediat HF is set to just recive and send, not doing any routing or filtering.&lt;BR /&gt;&lt;BR /&gt;Indexer is neither set to&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logdata-not-arriving-from-all-Universal-Forwarders/m-p/762619#M120741</guid>
      <dc:creator>erikwie</dc:creator>
      <dc:date>2026-07-30T10:58:52Z</dc:date>
    </item>
  </channel>
</rss>

