<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot Syslog-ng -&amp;gt; Splunk issue? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168002#M34015</link>
    <description>&lt;P&gt;We're running Linux 2.6.32-5...&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2013 18:04:24 GMT</pubDate>
    <dc:creator>echojacques</dc:creator>
    <dc:date>2013-12-05T18:04:24Z</dc:date>
    <item>
      <title>How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167996#M34009</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;My Splunk installation is configured to ingest data from many different sources.  Approximately half of the sources are direct (device -&amp;gt; Splunk) and the other half are indexed from a syslog-ng server (device -&amp;gt; syslog -&amp;gt; Splunk).  A few days ago, Splunk stopped indexing all data from the syslog server (about 10 different sourcetypes).  I checked connectivity between the syslog server and Splunk and everything seems fine.  I also rebooted the syslog server and Splunk.  So at this point, I'm not sure what else to do or how to investigate this issue since it's not specific to one source/sourcetype.  How can I troubleshoot this issue?  Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 15:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167996#M34009</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-12-05T15:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167997#M34010</link>
      <description>&lt;P&gt;Sounds like a problem with Syslog-ng.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Are you receiving events with Syslog-ng?&lt;/LI&gt;
&lt;LI&gt;Are you writing to file, or using tcp/udp to Splunk?
   ( Syslog -&amp;gt; NG -&amp;gt; file -&amp;gt; Splunk ) OR (Syslog -&amp;gt; NG -&amp;gt; syslog -&amp;gt; Splunk)&lt;/LI&gt;
&lt;LI&gt;Are you using a forwarder at all?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 05 Dec 2013 16:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167997#M34010</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-05T16:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167998#M34011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Yes, syslog-ng is receiving events.&lt;/LI&gt;
&lt;LI&gt;Writing to a file: syslog-ng -&amp;gt; file -&amp;gt; Splunk.&lt;/LI&gt;
&lt;LI&gt;I don't think so but how can I check if I am using a forwarder?  Splunk professional services setup our Splunk and I'm still learning the ropes.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 17:03:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167998#M34011</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-12-05T17:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167999#M34012</link>
      <description>&lt;P&gt;do you have "/opt/splunk" or "/opt/splunkforwarder" on the system?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 17:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/167999#M34012</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-05T17:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168000#M34013</link>
      <description>&lt;P&gt;I didn't find /opt/splunk or /opt/splunkforwarder in any of the splunk directories.  I do have /opt/ but the directory is empty.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 17:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168000#M34013</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-12-05T17:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168001#M34014</link>
      <description>&lt;P&gt;What OS do you have?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 17:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168001#M34014</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-05T17:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168002#M34015</link>
      <description>&lt;P&gt;We're running Linux 2.6.32-5...&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 18:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168002#M34015</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-12-05T18:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot Syslog-ng -&gt; Splunk issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168003#M34016</link>
      <description>&lt;P&gt;After some digging around, we figured it out: our splunk forwarder service wasn't running on our syslog server.  As soon as we started it, we started to see data from our syslog sources in Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 23:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-Syslog-ng-gt-Splunk-issue/m-p/168003#M34016</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-12-05T23:05:27Z</dc:date>
    </item>
  </channel>
</rss>

