<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File input stopped indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89048#M18489</link>
    <description>&lt;P&gt;My server doesn't accept connections on port 8089.  Is this something which has to be enabled?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2011 14:59:11 GMT</pubDate>
    <dc:creator>alan_watt</dc:creator>
    <dc:date>2011-04-26T14:59:11Z</dc:date>
    <item>
      <title>File input stopped indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89046#M18487</link>
      <description>&lt;P&gt;When I upgraded my home (free) SPLUNK from 4.2 to 4.2.1, it stopped indexing a number of files in /var/log, most notably "/var/log/messages".  It continued to index "/var/log/maillog" and several others, but a fair number of files in /var/log simply stopped indexing new input.&lt;/P&gt;

&lt;P&gt;The Data Input is defined as the entire directory "/var/log" with a whitelist and a blacklist.  I couldn't see anything wrong with the whitelist but I cleared it anyway -- no change.  The blacklist just contained "lastlog" (a binary file).&lt;/P&gt;

&lt;P&gt;The final indexed record was just minutes before the upgrade.  I reverted back to 4.2, but that did not fix the problem, so I re-upgraded to 4.2.1.&lt;/P&gt;

&lt;P&gt;I have searched the "_internal" index for activity involving "/var/log/messages" to look for any reason why new data is not indexed, but the only records I can find there are my own search commands.&lt;/P&gt;

&lt;P&gt;The files in /var/log are rotated &amp;amp; compressed weekly on Sunday, so since the upgrade (4/18) the file grew with new entries until Sunday (4/24), then started a completely new file, but none of this is in the indexes.&lt;/P&gt;

&lt;P&gt;I keep 4 weeks of rotated log files in /var/log, so if the indexing can be restarted somehow, all the missed data should be acquired.&lt;/P&gt;

&lt;P&gt;I should mention that when I upgraded previously from 4.1.7 to 4.2, it appeared all my previously indexed data got blown away and I started over as if it was a new install.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 14:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89046#M18487</guid>
      <dc:creator>alan_watt</dc:creator>
      <dc:date>2011-04-26T14:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: File input stopped indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89047#M18488</link>
      <description>&lt;P&gt;Can you hit https://&lt;YOURSERVERHERE&gt;:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus - if you scan down it'll tell you the status of each file it's indexing.&lt;/YOURSERVERHERE&gt;&lt;/P&gt;

&lt;P&gt;That should be a good starting point to see whats going on..&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 14:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89047#M18488</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-04-26T14:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: File input stopped indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89048#M18489</link>
      <description>&lt;P&gt;My server doesn't accept connections on port 8089.  Is this something which has to be enabled?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 14:59:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89048#M18489</guid>
      <dc:creator>alan_watt</dc:creator>
      <dc:date>2011-04-26T14:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: File input stopped indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89049#M18490</link>
      <description>&lt;P&gt;Ah.  I see the server will accept local connections to port 8089, but not from a remote system.  I don't see a setting for management port access list.  I can do this using a remote display&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 15:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89049#M18490</guid>
      <dc:creator>alan_watt</dc:creator>
      <dc:date>2011-04-26T15:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: File input stopped indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89050#M18491</link>
      <description>&lt;P&gt;There's another way to see whats happening, you can check out this blog entry by Amrit:  &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt;  &lt;/P&gt;

&lt;P&gt;Basically, we just need to figure out if splunk is actually reading the file or if for some reason it marked it as not readable due to crc issue, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2011 15:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-input-stopped-indexing/m-p/89050#M18491</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-04-26T15:49:56Z</dc:date>
    </item>
  </channel>
</rss>

