<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128794#M26437</link>
    <description>&lt;P&gt;So the syntax should be like this &lt;CODE&gt;[monitor://D:\Program*\...\vCAC\...\Logs\*]&lt;/CODE&gt; ? Will an asterisk (*) followed by ellipses (...) work in inputs.conf? Have you tried it before to monitor a path?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Nov 2014 14:28:54 GMT</pubDate>
    <dc:creator>erwinpastor</dc:creator>
    <dc:date>2014-11-21T14:28:54Z</dc:date>
    <item>
      <title>Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128788#M26431</link>
      <description>&lt;P&gt;I have configured the logs in the inputs.conf and added the servers in the serverclass.conf. Preliminary testing done to check if the client servers can connect to the splunk deployment server and communication port - all good.&lt;/P&gt;

&lt;P&gt;output.conf looks like the following:&lt;/P&gt;

&lt;P&gt;defaultGroup = zone1&lt;BR /&gt;
disabled = false&lt;BR /&gt;
[tcpout:zone1]&lt;BR /&gt;
server = deploymentserver:9996,heavyforwarederserver:9996&lt;/P&gt;

&lt;P&gt;[tcpout-server://deploymentserver:9996]&lt;BR /&gt;
[tcpout-server://heavyforwarder:9996]&lt;/P&gt;

&lt;P&gt;inputs.log looks like the following:&lt;/P&gt;

&lt;P&gt;[monitor://D:\Program Files (x86)...\vCAC...\Logs*]&lt;BR /&gt;
index = index_name&lt;BR /&gt;
sourcetype = sourcetype_name&lt;/P&gt;

&lt;P&gt;Additional info: servers have an existing WinEventlog and Perfmon setup in splunk.&lt;/P&gt;

&lt;P&gt;For some reason, the changes are not being picked up the splunk GUI.  Should there be any other config that needs to be done? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128788#M26431</guid>
      <dc:creator>erwinpastor</dc:creator>
      <dc:date>2020-09-28T18:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128789#M26432</link>
      <description>&lt;P&gt;The inputs.conf file you are talking about above, is that the &lt;CODE&gt;$splunk\etc\system\local\inputs.conf&lt;/CODE&gt; or &lt;CODE&gt;$splunk\etc\apps\deployment....\inputs.conf?&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 12:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128789#M26432</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2014-11-20T12:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128790#M26433</link>
      <description>&lt;P&gt;the one in &lt;CODE&gt;$splunk\etc\deployment....\inputs.conf&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 02:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128790#M26433</guid>
      <dc:creator>erwinpastor</dc:creator>
      <dc:date>2014-11-21T02:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128791#M26434</link>
      <description>&lt;P&gt;For one if the following syntax is what you actually have in your inputs.conf it is incorrect.&lt;BR /&gt;
You have: &lt;CODE&gt;[monitor://D:Program Files (x86)...vCAC...Logs*]&lt;/CODE&gt;&lt;BR /&gt;
You should have: &lt;CODE&gt;[monitor://D:\Program Files (x86)....vCAC....Logs.....*]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;you were missing the &lt;CODE&gt;"\"&lt;/CODE&gt; after the &lt;CODE&gt;"D:"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 11:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128791#M26434</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2014-11-21T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128792#M26435</link>
      <description>&lt;P&gt;Sorry, might have been omitted during the paste. But the actual syntaxt has &lt;CODE&gt;"\"&lt;/CODE&gt;  after the &lt;CODE&gt;"D:"&lt;/CODE&gt;.  So it is &lt;CODE&gt;[monitor://D:\Program Files (x86)\...\vCAC\...\Logs\*]&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 14:01:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128792#M26435</guid>
      <dc:creator>erwinpastor</dc:creator>
      <dc:date>2014-11-21T14:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128793#M26436</link>
      <description>&lt;P&gt;I've never tried to monitor a path with white spaces in the name. For testing purposes point it to a path with no spaces and see if you have any issues.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 14:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128793#M26436</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2014-11-21T14:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128794#M26437</link>
      <description>&lt;P&gt;So the syntax should be like this &lt;CODE&gt;[monitor://D:\Program*\...\vCAC\...\Logs\*]&lt;/CODE&gt; ? Will an asterisk (*) followed by ellipses (...) work in inputs.conf? Have you tried it before to monitor a path?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 14:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128794#M26437</guid>
      <dc:creator>erwinpastor</dc:creator>
      <dc:date>2014-11-21T14:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not seeing the logs in splunk GUI after configuring it in deployment servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128795#M26438</link>
      <description>&lt;P&gt;just tried doing without the spaces by editing the monitor to use &lt;CODE&gt;Program*&lt;/CODE&gt; but unfortunately it still didn't work.&lt;BR /&gt;
Any idea how Program Files or Program Files (x86) can be monitored in splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 02:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-seeing-the-logs-in-splunk-GUI-after-configuring-it/m-p/128795#M26438</guid>
      <dc:creator>erwinpastor</dc:creator>
      <dc:date>2014-11-25T02:22:32Z</dc:date>
    </item>
  </channel>
</rss>

