<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk stops receiving the data from clients in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61196#M12156</link>
    <description>&lt;P&gt;We have setup splunk in our environment, and we have logs coming in from different geographies (US/UK/Asia). The logs, all have different timestamps, but we have used a light forwarder to convert them all to current server time using ($SPLUNKHOME/etc/apps/search/local/props.conf):&lt;/P&gt;

&lt;P&gt;[host::x.*]&lt;/P&gt;

&lt;P&gt;DATETIME_CONFIG = CURRENT&lt;/P&gt;

&lt;P&gt;Also the inputs.conf and outputs.conf are properly configured, and everything works fine.&lt;BR /&gt;
But then after a few hours, i am unable to see any data coming from some of the machines (UK/Asia). I checked splunkd.log of light forwarder, there wasn't any ERROR in it. &lt;BR /&gt;
I checked metrics.log of forwarder, it seems to be getting updated with each update in UK/Asia machines, but no data is going to the splunk receiver.&lt;/P&gt;

&lt;P&gt;Checked splunkd.log at splunk receiver end, it contains this ERROR:&lt;BR /&gt;
09-17-2012 08:05:20.470 -0400 ERROR SearchResults - Unable to write to file '/opt/splunk/etc/users/abcd/search/history/hostname.csv'.  Retried 5 times, period=500 ms. error='No such file or directory'&lt;/P&gt;

&lt;P&gt;but i don't think that is related to the issue in any way.&lt;/P&gt;

&lt;P&gt;All clients and splunk receiver is on Linux, forwarder is on windows 2008.&lt;/P&gt;

&lt;P&gt;Can someone please help on how to debug the issue and what could be causing it?&lt;BR /&gt;
I have restored the system to a state (many times) where everything is working but then again the problem comes back.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2012 12:54:04 GMT</pubDate>
    <dc:creator>smmehadi</dc:creator>
    <dc:date>2012-09-17T12:54:04Z</dc:date>
    <item>
      <title>Splunk stops receiving the data from clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61196#M12156</link>
      <description>&lt;P&gt;We have setup splunk in our environment, and we have logs coming in from different geographies (US/UK/Asia). The logs, all have different timestamps, but we have used a light forwarder to convert them all to current server time using ($SPLUNKHOME/etc/apps/search/local/props.conf):&lt;/P&gt;

&lt;P&gt;[host::x.*]&lt;/P&gt;

&lt;P&gt;DATETIME_CONFIG = CURRENT&lt;/P&gt;

&lt;P&gt;Also the inputs.conf and outputs.conf are properly configured, and everything works fine.&lt;BR /&gt;
But then after a few hours, i am unable to see any data coming from some of the machines (UK/Asia). I checked splunkd.log of light forwarder, there wasn't any ERROR in it. &lt;BR /&gt;
I checked metrics.log of forwarder, it seems to be getting updated with each update in UK/Asia machines, but no data is going to the splunk receiver.&lt;/P&gt;

&lt;P&gt;Checked splunkd.log at splunk receiver end, it contains this ERROR:&lt;BR /&gt;
09-17-2012 08:05:20.470 -0400 ERROR SearchResults - Unable to write to file '/opt/splunk/etc/users/abcd/search/history/hostname.csv'.  Retried 5 times, period=500 ms. error='No such file or directory'&lt;/P&gt;

&lt;P&gt;but i don't think that is related to the issue in any way.&lt;/P&gt;

&lt;P&gt;All clients and splunk receiver is on Linux, forwarder is on windows 2008.&lt;/P&gt;

&lt;P&gt;Can someone please help on how to debug the issue and what could be causing it?&lt;BR /&gt;
I have restored the system to a state (many times) where everything is working but then again the problem comes back.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 12:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61196#M12156</guid>
      <dc:creator>smmehadi</dc:creator>
      <dc:date>2012-09-17T12:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stops receiving the data from clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61197#M12157</link>
      <description>&lt;P&gt;Can someone please help here, as this issue is blocking the logs from getting in splunk. It got reproduced on Linux too, when i installed forwarder on it.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2012 04:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61197#M12157</guid>
      <dc:creator>smmehadi</dc:creator>
      <dc:date>2012-09-19T04:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stops receiving the data from clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61198#M12158</link>
      <description>&lt;P&gt;I enabled deployment monitor app on server. It is showing up the forwarder as fine and there is a consistent connection between splunk server and forwarder. So then why my application server data have stopped showing up on server?&lt;/P&gt;

&lt;P&gt;splunk "All Forwarders" status in deployment monitor app is:&lt;/P&gt;

&lt;P&gt;my_forwarder    heavy forwarder 4.3.4   Linux   09/19/12 12:15:58 PM    09/19/12 12:15:58 PM    active  26.0500 0.0338&lt;/P&gt;

&lt;P&gt;splunk "All Indexer" status in deployment monitor app is:&lt;/P&gt;

&lt;P&gt;my_indexer  normal  09/19/12 12:00:38 PM    0.0000&lt;/P&gt;

&lt;P&gt;So then where the things can be going wrong???&lt;BR /&gt;
please help.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2012 06:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61198#M12158</guid>
      <dc:creator>smmehadi</dc:creator>
      <dc:date>2012-09-19T06:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stops receiving the data from clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61199#M12159</link>
      <description>&lt;P&gt;This type of question is environment specific. You should file a case with Splunk support on this. However, you could also check &lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;Troubleshooting Monitor Inputs on the Community Wiki&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2012 15:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61199#M12159</guid>
      <dc:creator>vgenovese</dc:creator>
      <dc:date>2012-09-19T15:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stops receiving the data from clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61200#M12160</link>
      <description>&lt;P&gt;I have narrowed down the problem to communication issue between jboss AS and forwarder.&lt;BR /&gt;
Recreating the problem from start:&lt;/P&gt;

&lt;P&gt;we have setup JBoss AS7 in our environment. our application servers are situated in different geographies (US/UK etc). splunk server/forwarders are situated in US and different geographies are connected by vpn. when the setup is ready, we restart application servers to make connection in raw mode to splunk forwarders.&lt;/P&gt;

&lt;P&gt;this works fine, but after an hour (or so) of sending log data from application servers to forwarders, UK servers stop sending the data to splunk forwarders.&lt;/P&gt;

&lt;P&gt;there isn't any ERROR in splunkd.log on forwarder, and the metrics.log shows that it is still having tcpin connection from UK machine.&lt;/P&gt;

&lt;P&gt;i created a shell script to send data from UK server on same tcp port of forwarder and it showed up fine in splunk server, so that means something went wrong between communication of jboss AS and forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2012 05:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stops-receiving-the-data-from-clients/m-p/61200#M12160</guid>
      <dc:creator>smmehadi</dc:creator>
      <dc:date>2012-09-20T05:42:41Z</dc:date>
    </item>
  </channel>
</rss>

