<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ubuntu 12.04 , rsyslog and splunk storm in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ubuntu-12-04-rsyslog-and-splunk-storm/m-p/86350#M17948</link>
    <description>&lt;P&gt;Hi pepepito,&lt;/P&gt;

&lt;P&gt;We had some issues with a searchhead yesterday. They should be resolved and you should be able to see your data now. If not, please file a Storm support ticket and we'll look into it!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ed&lt;/P&gt;</description>
    <pubDate>Sat, 06 Apr 2013 23:33:54 GMT</pubDate>
    <dc:creator>Ed</dc:creator>
    <dc:date>2013-04-06T23:33:54Z</dc:date>
    <item>
      <title>Ubuntu 12.04 , rsyslog and splunk storm</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ubuntu-12-04-rsyslog-and-splunk-storm/m-p/86349#M17947</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I just setup a free account in splunkstorm and try to set up rsyslog base on the documentation and I didn't see any data but strangely enough my 1G free is full but I don't see any data and even if I search nothing shows up.&lt;/P&gt;

&lt;P&gt;I get tons of this messages on the GUI :&lt;/P&gt;

&lt;P&gt;Reached end-of-stream while waiting for more data from peer mt-indexer-i-f49bed87.prod-root. Search results might be incomplete!&lt;/P&gt;

&lt;P&gt;my rsyslog file was :&lt;/P&gt;

&lt;P&gt;$ModLoad imuxsock # provides support for local system logging&lt;BR /&gt;
$ModLoad imklog   # provides kernel logging support (previously done by rklogd)&lt;BR /&gt;
$ModLoad imfile  # provides --MARK-- message capability&lt;/P&gt;

&lt;P&gt;$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat&lt;/P&gt;

&lt;P&gt;$RepeatedMsgReduction on&lt;/P&gt;

&lt;P&gt;$FileOwner syslog&lt;BR /&gt;
$FileGroup adm&lt;BR /&gt;
$FileCreateMode 0640&lt;BR /&gt;
$DirCreateMode 0755&lt;BR /&gt;
$Umask 0022&lt;BR /&gt;
$PrivDropToUser syslog&lt;BR /&gt;
$PrivDropToGroup syslog&lt;/P&gt;

&lt;P&gt;$WorkDirectory /var/spool/rsyslog&lt;/P&gt;

&lt;P&gt;$InputFileName /var/log/drupal.log &lt;BR /&gt;
$InputFileTag drupal:&lt;BR /&gt;
$InputFileStateFile stat-drupal&lt;BR /&gt;
$InputFileSeverity info &lt;BR /&gt;
$InputRunFileMonitor&lt;BR /&gt;
$InputFilePollingInterval 10&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;.&lt;/EM&gt; @@logs4.splunkstorm.com:20244&lt;BR /&gt;
$IncludeConfig /etc/rsyslog.d/*.conf&lt;/P&gt;

&lt;P&gt;In inputs network data page it says "Data last received" "N/A" but the storage is full, I don't get it.&lt;/P&gt;

&lt;P&gt;can someone help me to figure out this ?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;P.S : my timezone is setup to UTC 0000 on the server and splunkstorm&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ubuntu-12-04-rsyslog-and-splunk-storm/m-p/86349#M17947</guid>
      <dc:creator>pepepito</dc:creator>
      <dc:date>2013-04-05T20:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu 12.04 , rsyslog and splunk storm</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ubuntu-12-04-rsyslog-and-splunk-storm/m-p/86350#M17948</link>
      <description>&lt;P&gt;Hi pepepito,&lt;/P&gt;

&lt;P&gt;We had some issues with a searchhead yesterday. They should be resolved and you should be able to see your data now. If not, please file a Storm support ticket and we'll look into it!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ed&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2013 23:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ubuntu-12-04-rsyslog-and-splunk-storm/m-p/86350#M17948</guid>
      <dc:creator>Ed</dc:creator>
      <dc:date>2013-04-06T23:33:54Z</dc:date>
    </item>
  </channel>
</rss>

