<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder Data not showing in indexes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192942#M38487</link>
    <description>&lt;P&gt;Sorry for the mulitiple posts but this site wont let me post anything but a comment.&lt;/P&gt;

&lt;P&gt;Yes I upgraded the Forwarder software to be the same version as the Splunk install.  Current version of the both the Indexer and the Forwarder are: 6.0.1&lt;/P&gt;

&lt;P&gt;At first I did an upgrade and most recently I uninstalled the Forwarder and made sure the config files were deleted.  Then re-installed and reconfigured the Forwarder to send to the Splunk install.&lt;BR /&gt;
Below is what is contained in the inputs.conf and outputs.conf files on the Forwarder. (C:\Program Files\SplunkUniversalForwarder\etc\system\local)&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jan 2014 20:53:23 GMT</pubDate>
    <dc:creator>auragrp</dc:creator>
    <dc:date>2014-01-02T20:53:23Z</dc:date>
    <item>
      <title>Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192935#M38480</link>
      <description>&lt;P&gt;Recently I upgraded our Splunk installation from the 5 version to the new 6.0 version.&lt;/P&gt;

&lt;P&gt;The installation is pretty vanilla and has a single Splunk sever with one a secondary server using the Universal Forwarder to send IIS logs to the Splunk server.&lt;/P&gt;

&lt;P&gt;I noticed to my dismay that after the upgrade the new 6.0 version did not migrate my receiver port setting for the Forwarder to sent to. ie: port 9997&lt;/P&gt;

&lt;P&gt;Looking at the data listed in the indexes the last update listed is 12/3/13 on the Splunk server for the data source that is associated with the Forwarder.&lt;/P&gt;

&lt;P&gt;I have checked the Time, TimeZone and Date on both the Splunk and Forwarder server and they are the same.  I also checked the IIS logs that are being sent to verify time and date and what is listed is prior to the current time.&lt;/P&gt;

&lt;P&gt;I verified that the Forwarder configuration is reading the IIS logs and is configured to send to the Splunk server on the correct port.  I also made sure that the port is open on the firewall as it was on the 5.0 install. &lt;/P&gt;

&lt;P&gt;If I check the Deployment Monitor app &amp;gt; All Forwarders, I see the Forwarder server listed and the last Data Received as of 30 seconds ago.  &lt;/P&gt;

&lt;P&gt;But when searching All Time - Real-time I get: No results in current time range. &lt;/P&gt;

&lt;P&gt;So it looks to me like the Forwarder is sending and the Splunk server via the Deployment monitor says that it is receiving. But instead of adding the data to the indexes, the data looks like it is getting dumped.&lt;/P&gt;

&lt;P&gt;I will have to manually import the logs that have not made into the indexes eventually when I get this working.  But in the mean time anyone have any thoughts or ideas of how to fix this?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 00:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192935#M38480</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-01T00:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192936#M38481</link>
      <description>&lt;P&gt;Sorry if this is a dumb question, but are you sure that you are searching all the indexes? One of the things that might have changed when you installed Splunk 6 (depending on how you did it) -&amp;gt; the default indexes searched by a role. I would check the role. Also, try this search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* host=theHostName
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Jan 2014 01:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192936#M38481</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-01T01:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192937#M38482</link>
      <description>&lt;P&gt;thanks for the response, but unfortunately I have checked that and the only data that is showing is the historic data from before the upgrade.&lt;/P&gt;

&lt;P&gt;I have tried it both ways ie:&lt;BR /&gt;
 1. index=* host=theHostName&lt;BR /&gt;
 2. index=* &lt;BR /&gt;
(the post is removing the asterisk but it is there.)&lt;/P&gt;

&lt;P&gt;Both only show latest data from just before the upgrade.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 01:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192937#M38482</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-01T01:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192938#M38483</link>
      <description>&lt;P&gt;below what is listed in the Data Summary popup inside the Search app:&lt;BR /&gt;
Host:  MC-TRACKING&lt;BR /&gt;
Count:  2,134,522&lt;BR /&gt;
Last Update:  12/3/13 6:17:13:00 PM&lt;/P&gt;

&lt;P&gt;Below is information from Deployment monitor:&lt;BR /&gt;
Forwarder: MC-TRACKING&lt;BR /&gt;
Splunk Version:  6.0.1&lt;BR /&gt;
Forwarder Type:  universal forwarder&lt;BR /&gt;
Platform:  Windows&lt;BR /&gt;
Last Connected: 12/31/13 17:30:00 PM&lt;BR /&gt;
Last Data Received:  12/31/13 17:33:51 PM&lt;BR /&gt;
Current Status:  active&lt;BR /&gt;
Total KB:  9.6190&lt;BR /&gt;
Average Events Per Second:  0.3232&lt;/P&gt;

&lt;P&gt;So I am at a loss of why the data is being seen and received by the Deployment monitor but is not being added to the indexes so that it can be viewed.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 01:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192938#M38483</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-01T01:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192939#M38484</link>
      <description>&lt;P&gt;It is possible that the data being sent is just the forwarder's Splunk internal logs. &lt;/P&gt;

&lt;P&gt;Try this search and see what you get:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=_internal MC-TRACKING&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;or replace &lt;CODE&gt;MC-TRACKING&lt;/CODE&gt; with the name of one of the sources you want to monitor.&lt;/P&gt;

&lt;P&gt;Also, take a look at this article on the wiki -&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 02:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192939#M38484</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-01T02:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192940#M38485</link>
      <description>&lt;P&gt;yes you are correct that the only data is internal.  so the log files that should be sent are not being sent.&lt;BR /&gt;
I just tried uninstalling the forwarder, delete the config, reboot and install from scratch.&lt;BR /&gt;
When I install I specifically only select the IIS log directory as what will be sent.  When I search with: host="MC-TRACKING"  now the data that I am seeing is WinEventLog:System events that I did not tell the Forward to send.&lt;BR /&gt;
Still no IIS logs being sent.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 20:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192940#M38485</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-01T20:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192941#M38486</link>
      <description>&lt;P&gt;What it sounds like is that you might have had your configurations in .../default/ directories... and that they were overwritten.  Did you upgrade the forwarder as well as the indexer?  you haven't mentioned what the actual settings are in the config files. Of interest would be inputs.conf and outputs.conf on the forwarder and inputs.conf on the indexer.  you also mentioned that the upgrade didn't preserve the receiving port on the indexer. Do you mean that it seemed to have wiped it out on both the forwarder and indexer or just on one end?  but it does sound like lost configurations.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2014 22:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192941#M38486</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2014-01-01T22:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192942#M38487</link>
      <description>&lt;P&gt;Sorry for the mulitiple posts but this site wont let me post anything but a comment.&lt;/P&gt;

&lt;P&gt;Yes I upgraded the Forwarder software to be the same version as the Splunk install.  Current version of the both the Indexer and the Forwarder are: 6.0.1&lt;/P&gt;

&lt;P&gt;At first I did an upgrade and most recently I uninstalled the Forwarder and made sure the config files were deleted.  Then re-installed and reconfigured the Forwarder to send to the Splunk install.&lt;BR /&gt;
Below is what is contained in the inputs.conf and outputs.conf files on the Forwarder. (C:\Program Files\SplunkUniversalForwarder\etc\system\local)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2014 20:53:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192942#M38487</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-02T20:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192943#M38488</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Inputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
[default]&lt;BR /&gt;
host = MC-TRACKING&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Outputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = domainname.com:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://domainname.com:9997]&lt;/P&gt;

&lt;P&gt;The only thing that I see that is being sent from the server with the Forwarder is Windows System log information.  Which when I setup the forwarder I told it not to send. The only thing it should be sending is the log files I told it to send was the IIS logs specific for one site.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2014 20:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192943#M38488</guid>
      <dc:creator>auragrp</dc:creator>
      <dc:date>2014-01-02T20:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data not showing in indexes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192944#M38489</link>
      <description>&lt;P&gt;I don't see anything about the IIS logs in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; so perhaps you have more than one &lt;CODE&gt;inputs.conf&lt;/CODE&gt; under &lt;CODE&gt;$SPLUNK_HOME\etc&lt;/CODE&gt; (which would be pretty common). If you don't have any other &lt;CODE&gt;inputs.conf&lt;/CODE&gt; on your forwarder, then it is clear that the input you want is simply not specified...&lt;/P&gt;

&lt;P&gt;Also  the input for the script is actually &lt;EM&gt;enabled&lt;/EM&gt;, so perhaps you want to turn it off:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That may solve your problems with the Windows System log information.&lt;/P&gt;

&lt;P&gt;Finally, did you install any apps or add-ons on the forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2015 22:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-not-showing-in-indexes/m-p/192944#M38489</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-01-06T22:24:20Z</dc:date>
    </item>
  </channel>
</rss>

