<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor stanza in inputs.conf not working, data is not getting indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202106#M40004</link>
    <description>&lt;P&gt;Have you previously indexed these files into another index (say, maybe a test index) and have since switched the index that you want to contain the data? If so, have the source files that you are trying to index changed?&lt;/P&gt;

&lt;P&gt;It's a stretch, but maybe try changing your crcsalt?&lt;/P&gt;

&lt;P&gt;Have you had any success testing out your data with a oneshot command? &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorfilesanddirectoriesusingtheCLI#CLI_commands_for_input_configuration"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorfilesanddirectoriesusingtheCLI#CLI_commands_for_input_configuration&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2015 16:12:03 GMT</pubDate>
    <dc:creator>tlelle_splunk</dc:creator>
    <dc:date>2015-08-31T16:12:03Z</dc:date>
    <item>
      <title>monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202099#M39997</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;

&lt;P&gt;Below is my inputs.conf stanza which we have in forwarders server in the below path. SplnkFwdrinputs is the app name which we have created in deployment server and pushed to the forwarder by defining the serverclass&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/apps/SplnkFwdrinputs/local&lt;/P&gt;

&lt;P&gt;[monitor:///opt/softwareag/profiles/IS/workspace/temp/splunkStorage]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
sourcetype = TMF_XML&lt;BR /&gt;
index = WMTMF&lt;BR /&gt;
crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;

&lt;P&gt;We have created the index as well in the indexer server and we could see the index in the indexer server with name WMTMF.&lt;/P&gt;

&lt;P&gt;we have all .xml files in the /opt/softwareag/profiles/IS/workspace/temp/splunkStorage path but we are not able to see any data in the indexer&lt;/P&gt;

&lt;P&gt;we have defined the stanza in props.conf of indexer server to handle the xml files which is working as expected, same has been tested with manual upload.&lt;/P&gt;

&lt;P&gt;we could see all the xml files when we give the command ./splunk monitor list inputs&lt;/P&gt;

&lt;P&gt;Not sure what am I missing here?&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:03:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202099#M39997</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-08-31T15:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202100#M39998</link>
      <description>&lt;P&gt;Did you try restarting splunkd?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:17:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202100#M39998</guid>
      <dc:creator>jensonthottian</dc:creator>
      <dc:date>2015-08-31T15:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202101#M39999</link>
      <description>&lt;P&gt;Thanks jensonthottian for your response.&lt;/P&gt;

&lt;P&gt;Yes I did that..Still no luck.&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202101#M39999</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-08-31T15:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202102#M40000</link>
      <description>&lt;P&gt;What does your outputs.conf look like? Were you already able to onboard data previously from this machine?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202102#M40000</guid>
      <dc:creator>tlelle_splunk</dc:creator>
      <dc:date>2015-08-31T15:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202103#M40001</link>
      <description>&lt;P&gt;Hi tlelle,&lt;/P&gt;

&lt;P&gt;Thanks for your response.&lt;/P&gt;

&lt;P&gt;outputs.conf is in /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = indexerip:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://indexerip:9997]&lt;/P&gt;

&lt;P&gt;No first time i'm trying to push data from this machine.&lt;/P&gt;

&lt;P&gt;even I have tried the same in another environment as well, same issue, not sure what i'm missing.&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:26:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202103#M40001</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-08-31T15:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202104#M40002</link>
      <description>&lt;P&gt;You can take out &lt;/P&gt;

&lt;P&gt;[tcpout-server://indexerip:9997] &lt;/P&gt;

&lt;P&gt;from your outputs.conf, assuming that you have an actual IP listed in the line &lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = indexerip:9997&lt;/P&gt;

&lt;P&gt;also try the command ./splunk list forward-server to ensure that the connection to your indexer is active.&lt;/P&gt;

&lt;P&gt;If you make the changes and the server is still showing inactive, ensure that port 9997 is open on your indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202104#M40002</guid>
      <dc:creator>tlelle_splunk</dc:creator>
      <dc:date>2015-08-31T15:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202105#M40003</link>
      <description>&lt;P&gt;Hi tlelle,&lt;/P&gt;

&lt;P&gt;Yes correct, I have mentioned actual ip in that stanza instead of "indexerip"&lt;/P&gt;

&lt;P&gt;I have removed the [tcpout-server://indexerip:9997] stanza from outputs.conf&lt;/P&gt;

&lt;P&gt;I have one forwarder  indexerip:9997 with active list in my forwarder servr.&lt;/P&gt;

&lt;P&gt;Still i'm not able to see any data in my indexer&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 15:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202105#M40003</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-08-31T15:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202106#M40004</link>
      <description>&lt;P&gt;Have you previously indexed these files into another index (say, maybe a test index) and have since switched the index that you want to contain the data? If so, have the source files that you are trying to index changed?&lt;/P&gt;

&lt;P&gt;It's a stretch, but maybe try changing your crcsalt?&lt;/P&gt;

&lt;P&gt;Have you had any success testing out your data with a oneshot command? &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorfilesanddirectoriesusingtheCLI#CLI_commands_for_input_configuration"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorfilesanddirectoriesusingtheCLI#CLI_commands_for_input_configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 16:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202106#M40004</guid>
      <dc:creator>tlelle_splunk</dc:creator>
      <dc:date>2015-08-31T16:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202107#M40005</link>
      <description>&lt;P&gt;Have you performed a tcp dump from the source host to see if the forwarder is attempting to send the data to your indexer on tcp port 9997 ? Also, is any eventdata at all being indexed from this universal forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 16:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202107#M40005</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-08-31T16:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202108#M40006</link>
      <description>&lt;P&gt;Hi tlelle,&lt;/P&gt;

&lt;P&gt;Thanks for your responses.&lt;/P&gt;

&lt;P&gt;I have tried all the steps mentioned, still no luck.&lt;/P&gt;

&lt;P&gt;surprisingly if i'm not mentioning then it is getting indexed in default index&lt;/P&gt;

&lt;P&gt;So I believe it is only problem with the indexes other than default "main" index.&lt;/P&gt;

&lt;P&gt;I have created those index manually before  pushing this data , not sure where is the issue?&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 11:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202108#M40006</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-09-01T11:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202109#M40007</link>
      <description>&lt;P&gt;Hi tskinnerivsec,&lt;/P&gt;

&lt;P&gt;Thanks for your responses.&lt;/P&gt;

&lt;P&gt;I have tried all the steps mentioned, still no luck.&lt;/P&gt;

&lt;P&gt;surprisingly if i'm not mentioning then it is getting indexed in default index&lt;/P&gt;

&lt;P&gt;So I believe it is only problem with the indexes other than default "main" index.&lt;/P&gt;

&lt;P&gt;I have created those index manually before  pushing this data , not sure where is the issue?&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 11:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202109#M40007</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-09-01T11:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202110#M40008</link>
      <description>&lt;P&gt;You need to see what props and transforms have been applied to that sourcetype on the indexers. If the data is showing up in main, then the file monitor itself is working and communication to the indexers is ok. A configuration on the indexers may be getting applied to the sourcetype and overriding the index it is being directed to.&lt;/P&gt;

&lt;P&gt;on the indexers try this from the /splunk/bin directory&lt;/P&gt;

&lt;P&gt;./splunk btool list props &amp;gt; props_list.txt&lt;/P&gt;

&lt;P&gt;then, look through that file for a line that says&lt;BR /&gt;
[TMF_XML]&lt;/P&gt;

&lt;P&gt;The stanzas below that line will indicate what is being applied to that sourcetype. A clue to your issue may rest&lt;BR /&gt;
in one of those configuration stanzas.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 12:29:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202110#M40008</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-09-01T12:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202111#M40009</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have below for [TMF_XML] stanza in props.conf in indexer server&lt;/P&gt;

&lt;P&gt;[TMF_XML]&lt;BR /&gt;
ANNOTATE_PUNCT = True&lt;BR /&gt;
AUTO_KV_JSON = true&lt;BR /&gt;
BREAK_ONLY_BEFORE = \&lt;BR /&gt;
BREAK_ONLY_BEFORE_DATE = false&lt;BR /&gt;
CHARSET = AUTO&lt;BR /&gt;
DATETIME_CONFIG = \etc\datetime.xml&lt;BR /&gt;
HEADER_MODE = &lt;BR /&gt;
KV_MODE = xml&lt;BR /&gt;
LEARN_SOURCETYPE = true&lt;BR /&gt;
LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
MAX_DAYS_AGO = 2000&lt;BR /&gt;
MAX_DAYS_HENCE = 2&lt;BR /&gt;
MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
MAX_EVENTS = 256&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
MUST_BREAK_AFTER = &lt;BR /&gt;
MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
REPORT-xmlext = xml-extr&lt;BR /&gt;
SEGMENTATION = indexing&lt;BR /&gt;
SEGMENTATION-all = full&lt;BR /&gt;
SEGMENTATION-inner = inner&lt;BR /&gt;
SEGMENTATION-outer = outer&lt;BR /&gt;
SEGMENTATION-raw = none&lt;BR /&gt;
SEGMENTATION-standard = standard&lt;BR /&gt;
SHOULD_LINEMERGE = True&lt;BR /&gt;
TRANSFORMS = &lt;BR /&gt;
TRUNCATE = 10000&lt;BR /&gt;
category = Custom&lt;BR /&gt;
detect_trailing_nulls = auto&lt;BR /&gt;
disabled = false&lt;BR /&gt;
maxDist = 100&lt;BR /&gt;
priority = &lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
sourcetype = &lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202111#M40009</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2020-09-29T07:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202112#M40010</link>
      <description>&lt;P&gt;I also just noticed, your index name is upper case, which could be causing issues. Per splunkdocs:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;To create a new index, enter:&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;A name for the index. User-defined index names must consist of only numbers, lowercase letters, underscores, and hyphens. They cannot begin with an underscore or hyphen, or contain the word "kvstore".&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Setupmultipleindexes"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Setupmultipleindexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;you may want to change that, edit your file monitor, and see if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202112#M40010</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-09-01T13:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202113#M40011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Yes, event i have noticed that and changed the index name in inputs.conf with lower case, still no luck.&lt;/P&gt;

&lt;P&gt;can you please see the above props.conf , is there any issue with that [TMF_XML] stanza?&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202113#M40011</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-09-01T13:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202114#M40012</link>
      <description>&lt;P&gt;I saw new issues with the props.conf. The inputs.conf file is not the only thing that needed to get changed. Did you recreate the index in lower case? If not, create the new index.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:15:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202114#M40012</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-09-01T13:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202115#M40013</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have created new index with lowercase with name wmtmf1 and updated the inputs.conf, still it is same.&lt;/P&gt;

&lt;P&gt;can you please tell me the issues with props.conf &lt;/P&gt;

&lt;P&gt;Above result is the output of ./splunk btool list props &amp;gt; props_list.txt&lt;/P&gt;

&lt;P&gt;-Krishna Rajapantula.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202115#M40013</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2015-09-01T13:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: monitor stanza in inputs.conf not working, data is not getting indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202116#M40014</link>
      <description>&lt;P&gt;Sorry, meant, I saw no issues with props, not new.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-stanza-in-inputs-conf-not-working-data-is-not-getting/m-p/202116#M40014</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-09-01T13:29:18Z</dc:date>
    </item>
  </channel>
</rss>

