<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic windows splunk forwarder not sending data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166151#M33692</link>
    <description>&lt;P&gt;My Server monitors 4 0ut of 5&lt;BR /&gt;
The one below does not get monitored:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Windows\System32\LogFiles\HTTPERR\httperr1.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf referring to this instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Windows\System32\LogFiles\HTTPERR]
disabled = false
followTail = 0
host = iis.windowsservername
sourcetype = iis_error
blacklist = \.gz$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 26 Feb 2014 13:33:12 GMT</pubDate>
    <dc:creator>muhammad4</dc:creator>
    <dc:date>2014-02-26T13:33:12Z</dc:date>
    <item>
      <title>windows splunk forwarder not sending data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166151#M33692</link>
      <description>&lt;P&gt;My Server monitors 4 0ut of 5&lt;BR /&gt;
The one below does not get monitored:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Windows\System32\LogFiles\HTTPERR\httperr1.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf referring to this instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Windows\System32\LogFiles\HTTPERR]
disabled = false
followTail = 0
host = iis.windowsservername
sourcetype = iis_error
blacklist = \.gz$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Feb 2014 13:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166151#M33692</guid>
      <dc:creator>muhammad4</dc:creator>
      <dc:date>2014-02-26T13:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: windows splunk forwarder not sending data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166152#M33693</link>
      <description>&lt;P&gt;There are lots of possible reasons for your events not being seen where you expect them.&lt;/P&gt;

&lt;P&gt;Start here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Apart from that, it might be a good idea to see what the forwarder thinks it is doing with the file by querying this url;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://your_forwarder:8089/services/admin/inputstatus/TailingProcessor:FileStatus"&gt;https://your_forwarder:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You might also want to investigate this setting in inputs.conf on the forwarder.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;alwaysOpenFile = [0|1]
 * Opens a file to check whether it has already been indexed.
 * Only useful for files that do not update modtime.
 * Only needed when monitoring files on Windows, mostly for IIS logs.
 * This flag should only be used as a last resort, as it increases load and slows down indexing.
 * Defaults to 0.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 14:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166152#M33693</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-02-26T14:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: windows splunk forwarder not sending data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166153#M33694</link>
      <description>&lt;P&gt;Thank you.   dam spaces  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;thanks again  for your response&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 15:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/windows-splunk-forwarder-not-sending-data/m-p/166153#M33694</guid>
      <dc:creator>muhammad4</dc:creator>
      <dc:date>2014-02-26T15:25:13Z</dc:date>
    </item>
  </channel>
</rss>

