<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs Not Being Indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168506#M34115</link>
    <description>&lt;P&gt;Has the index been defined in indexes.conf or via the GUI? What does the _internal index say?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2014 16:06:10 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2014-02-27T16:06:10Z</dc:date>
    <item>
      <title>Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168497#M34106</link>
      <description>&lt;P&gt;I'm fairly new to Splunk and I can't figure out how to get Splunk to index my logs. I have configured my WebSense device to send logs to Splunk on UDP 6667 and I have configured Splunk to listen for logs on UDP 6667. I did a packet capture to make sure the logs were getting sent to the Splunk server. I have confirmed that they are getting sent to the server, but I cannot search through the logs. I believe the logs are not being properly indexed. Any ideas? &lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 14:17:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168497#M34106</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T14:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168498#M34107</link>
      <description>&lt;P&gt;Did you have set the sourcetype and the index when you configured Splunk?&lt;BR /&gt;
Did you edited your local copy of props.conf and trasform.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 14:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168498#M34107</guid>
      <dc:creator>emaccaferri</dc:creator>
      <dc:date>2014-02-27T14:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168499#M34108</link>
      <description>&lt;P&gt;I set the sourcetype and index in the inputs.conf file. What do I need to edit in the props.conf and transform.conf files?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 14:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168499#M34108</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T14:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168500#M34109</link>
      <description>&lt;P&gt;What is your search that isn't working?&lt;/P&gt;

&lt;P&gt;It might be a matter of time. Some logs from devices send in UTC, but if you are in EST, they won't show up! Try adding "latest=+10h@h" to your search and see if that makes your logs show up.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 14:45:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168500#M34109</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-27T14:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168501#M34110</link>
      <description>&lt;P&gt;I am doing the most basic search something like "index=websense" just to see if the logs are even being indexed into Splunk and I'm getting no results. I tried adding "latest=+10h@h" that didn't work.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 15:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168501#M34110</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T15:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168502#M34111</link>
      <description>&lt;P&gt;Try looking in index=main or index=default. or just do "index=*" and see if they show. Make sure that index=websense is part of your inputs configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 15:47:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168502#M34111</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-27T15:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168503#M34112</link>
      <description>&lt;P&gt;index=main returns a lot of logs from Perfmon:LocalNetwork that look like this:&lt;/P&gt;

&lt;P&gt;02/27/2014 10:55:26.775&lt;BR /&gt;
collection=LocalNetwork&lt;BR /&gt;
object="Network Interface"&lt;BR /&gt;
counter="Current Bandwidth"&lt;BR /&gt;
instance="Broadcom BCM5709C NetXtreme II GigE [NDIS VBD Client] _6"&lt;BR /&gt;
Value=1000000000&lt;/P&gt;

&lt;P&gt;Is it possible that those are the logs I want but the correct information isn't being extracted? &lt;/P&gt;

&lt;P&gt;From inputs.conf&lt;BR /&gt;
[udp://:6667]&lt;BR /&gt;
sourcetype = websense&lt;BR /&gt;
index = websense&lt;BR /&gt;
disabled = false&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 15:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168503#M34112</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T15:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168504#M34113</link>
      <description>&lt;P&gt;There's your typo - you have an extra :&lt;/P&gt;

&lt;P&gt;Should be: &lt;CODE&gt;[udp://6667]&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168504#M34113</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-27T16:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168505#M34114</link>
      <description>&lt;P&gt;Yea, I tried it with and without that colon. Still wasn't working. I should be setting this in /etc/apps/websense/local correct?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168505#M34114</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T16:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168506#M34115</link>
      <description>&lt;P&gt;Has the index been defined in indexes.conf or via the GUI? What does the _internal index say?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168506#M34115</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-27T16:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168507#M34116</link>
      <description>&lt;P&gt;_internal index returned no results, I tried to set an index via the GUI and got the following error: "Timed out while waiting for splunkd daemon to respond. Splunkd may be hung." So I went into the server and configured /etc/apps/websense/local/indexes.conf with the following:&lt;/P&gt;

&lt;P&gt;[websense]&lt;BR /&gt;
homePath = $SPLUNK_DB\websense\db&lt;BR /&gt;
maxDataSize = auto_high_volume&lt;BR /&gt;
thawedPath = $SPLUNK_DB\websense\thaweddb&lt;BR /&gt;
coldPath = $SPLUNK_DB\websense\colddb&lt;/P&gt;

&lt;P&gt;Does that look correct? For some reason the backslashes are getting removed when I click comment, but they are in the config.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168507#M34116</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2020-09-28T15:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168508#M34117</link>
      <description>&lt;P&gt;Looks good to me, restart Splunk for it to take effect.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168508#M34117</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-27T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168509#M34118</link>
      <description>&lt;P&gt;Still no results.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168509#M34118</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T16:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168510#M34119</link>
      <description>&lt;P&gt;This may be a stretch, but I know my instance of Splunk listens for traffic from forwarders on TCP 6667. Could this be interfering with the UDP traffic? I know you can use the same port concurrently with both UDP and TCP but would doing this be an issue in Splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 17:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168510#M34119</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-27T17:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168511#M34120</link>
      <description>&lt;P&gt;They shouldn't interfere with each other. Check the physical size of the index (The FireBrigade App can help with this). If the physical size isn't changing, you may have a listening problem.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 13:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168511#M34120</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-02-28T13:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168512#M34121</link>
      <description>&lt;P&gt;I'm getting this error when trying to use the Fire Brigade App "Unable to fetch REST endpoint uri="/services/data/indexes?count=0" from server="&lt;SERVER&gt;"." I also am getting a lot of N/A, No results found when trying to use this app. Do I need to do some initial setup with this app?&lt;/SERVER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 15:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168512#M34121</guid>
      <dc:creator>cuppma</dc:creator>
      <dc:date>2014-02-28T15:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Logs Not Being Indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168513#M34122</link>
      <description>&lt;P&gt;You're forgetting directory slashes here. &lt;/P&gt;

&lt;P&gt;homePath = $SPLUNK_DB/websensedb. &lt;/P&gt;

&lt;P&gt;Unless you have a variable set for $SPLUNK_DBwebsensedb defined.  Have you looked in $SPLUNK_HOME/var/lib/splunk to see if the index is there? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:44:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-Not-Being-Indexed/m-p/168513#M34122</guid>
      <dc:creator>mgonter</dc:creator>
      <dc:date>2020-09-29T06:44:08Z</dc:date>
    </item>
  </channel>
</rss>

