<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No indexers have reported into this pool today in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130329#M26800</link>
    <description>&lt;P&gt;I made no changes to the inputs.conf files on the forwarders.  The only change I made was to the props.conf on the indexer.  I just went to double check the settings in \default\props.conf and the file was empty!  That seems to be the source of the problem.  Not sure how that happened, but I reverted the file back and now I see events being indexed as expected.&lt;BR /&gt;&lt;BR /&gt;
Thanks LUKEJADAMEC for sparking me to look in the right spot!&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2014 06:40:57 GMT</pubDate>
    <dc:creator>verifybrand</dc:creator>
    <dc:date>2014-01-30T06:40:57Z</dc:date>
    <item>
      <title>No indexers have reported into this pool today</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130327#M26798</link>
      <description>&lt;P&gt;On Monday, I applied a reset license, as the indexing got out of hand last week and seemed to be indexing duplicate logs files.&lt;BR /&gt;
Now today, when I check the pool, it says this:&lt;/P&gt;

&lt;P&gt;No indexers have reported into this pool today&lt;/P&gt;

&lt;P&gt;I've restarted all the Splunk Forwarders on the servers (8 total).  I've restarted the splunk server.  This was all working and functional previously.  Firewalls are configured to allow port 9997.&lt;/P&gt;

&lt;P&gt;Any ideas on what the issue is?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 22:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130327#M26798</guid>
      <dc:creator>verifybrand</dc:creator>
      <dc:date>2014-01-29T22:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: No indexers have reported into this pool today</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130328#M26799</link>
      <description>&lt;P&gt;Did you make changes to the inputs.conf files to correct for the indexing overload?&lt;BR /&gt;
Are you getting messages in the forwarders splunkd.log files that say the something to the effect that 'connection to the indexer was refused'?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 01:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130328#M26799</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-30T01:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: No indexers have reported into this pool today</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130329#M26800</link>
      <description>&lt;P&gt;I made no changes to the inputs.conf files on the forwarders.  The only change I made was to the props.conf on the indexer.  I just went to double check the settings in \default\props.conf and the file was empty!  That seems to be the source of the problem.  Not sure how that happened, but I reverted the file back and now I see events being indexed as expected.&lt;BR /&gt;&lt;BR /&gt;
Thanks LUKEJADAMEC for sparking me to look in the right spot!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 06:40:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-indexers-have-reported-into-this-pool-today/m-p/130329#M26800</guid>
      <dc:creator>verifybrand</dc:creator>
      <dc:date>2014-01-30T06:40:57Z</dc:date>
    </item>
  </channel>
</rss>

