<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgraded Universal Forwarder, log file no longer monitored in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Universal-Forwarder-log-file-no-longer-monitored/m-p/127576#M26217</link>
    <description>&lt;P&gt;Hey all,&lt;/P&gt;

&lt;P&gt;I'm able to successfully monitor a log file on a Windows server (2008 R2) using the Universal Forwarder while on version 4.3.1. The entry in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; is a simple &lt;CODE&gt;[monitor://&amp;lt;path to file&amp;gt;]&lt;/CODE&gt;, no additional options are used.&lt;/P&gt;

&lt;P&gt;I performed an in place upgrade to UF 6.0.2 and I don't get anything from that file indexed anymore. I still get event log entries, it's just that specific file that is not being indexed.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;splunkd.log&lt;/CODE&gt; on the host shows the file is being monitored as I see the &lt;CODE&gt;TailingProcessor&lt;/CODE&gt; entries mentioning the stanza. &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; shows the file is being monitored.&lt;/P&gt;

&lt;P&gt;Any ideas on how to debug this?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2014 17:53:04 GMT</pubDate>
    <dc:creator>gustavomichels</dc:creator>
    <dc:date>2014-04-10T17:53:04Z</dc:date>
    <item>
      <title>Upgraded Universal Forwarder, log file no longer monitored</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Universal-Forwarder-log-file-no-longer-monitored/m-p/127576#M26217</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;

&lt;P&gt;I'm able to successfully monitor a log file on a Windows server (2008 R2) using the Universal Forwarder while on version 4.3.1. The entry in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; is a simple &lt;CODE&gt;[monitor://&amp;lt;path to file&amp;gt;]&lt;/CODE&gt;, no additional options are used.&lt;/P&gt;

&lt;P&gt;I performed an in place upgrade to UF 6.0.2 and I don't get anything from that file indexed anymore. I still get event log entries, it's just that specific file that is not being indexed.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;splunkd.log&lt;/CODE&gt; on the host shows the file is being monitored as I see the &lt;CODE&gt;TailingProcessor&lt;/CODE&gt; entries mentioning the stanza. &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; shows the file is being monitored.&lt;/P&gt;

&lt;P&gt;Any ideas on how to debug this?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 17:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Universal-Forwarder-log-file-no-longer-monitored/m-p/127576#M26217</guid>
      <dc:creator>gustavomichels</dc:creator>
      <dc:date>2014-04-10T17:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Universal Forwarder, log file no longer monitored</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Universal-Forwarder-log-file-no-longer-monitored/m-p/127577#M26218</link>
      <description>&lt;P&gt;I guess I didn't wait long enough. Problem was entries were being indexed with the wrong timestamp. Indexer is in GMT, host is in UTC, so I needed to add &lt;CODE&gt;_tzhint=UTC&lt;/CODE&gt; to the monitor stanza.&lt;/P&gt;

&lt;P&gt;All set now.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 18:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Universal-Forwarder-log-file-no-longer-monitored/m-p/127577#M26218</guid>
      <dc:creator>gustavomichels</dc:creator>
      <dc:date>2014-04-10T18:30:41Z</dc:date>
    </item>
  </channel>
</rss>

