<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to find lost logs from universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214666#M42226</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've a universal forwarder on a Linux machine that forwards Security Onion logs to my Splunk instance.&lt;/P&gt;

&lt;P&gt;Logs are coming to network interface via port 9998 (checked tcpdump), When I try to search with;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal metrics kb group=per_sourcetype_thruput | eval sizeMB = round(kb/1024,2)| stats sum(sizeMB) by series | sort -sum(sizeMB) | rename sum(sizeMB) AS "Size on Disk (MB)" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It shows source names etc. and logs are coming to my instance but when I try to see the logs, I can't find the logs. They're being saved somewhere but I can't figure out the search to see them.&lt;/P&gt;

&lt;P&gt;How can i do this?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2016 13:06:28 GMT</pubDate>
    <dc:creator>ozirus</dc:creator>
    <dc:date>2016-11-08T13:06:28Z</dc:date>
    <item>
      <title>How to find lost logs from universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214666#M42226</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've a universal forwarder on a Linux machine that forwards Security Onion logs to my Splunk instance.&lt;/P&gt;

&lt;P&gt;Logs are coming to network interface via port 9998 (checked tcpdump), When I try to search with;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal metrics kb group=per_sourcetype_thruput | eval sizeMB = round(kb/1024,2)| stats sum(sizeMB) by series | sort -sum(sizeMB) | rename sum(sizeMB) AS "Size on Disk (MB)" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It shows source names etc. and logs are coming to my instance but when I try to see the logs, I can't find the logs. They're being saved somewhere but I can't figure out the search to see them.&lt;/P&gt;

&lt;P&gt;How can i do this?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 13:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214666#M42226</guid>
      <dc:creator>ozirus</dc:creator>
      <dc:date>2016-11-08T13:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to find lost logs from universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214667#M42227</link>
      <description>&lt;P&gt;You could have a timestamp problem.  Try searching All Time to see if Splunk is logging the events in the future.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 13:19:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214667#M42227</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2016-11-08T13:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to find lost logs from universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214668#M42228</link>
      <description>&lt;P&gt;Thanks! It was.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 13:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214668#M42228</guid>
      <dc:creator>ozirus</dc:creator>
      <dc:date>2016-11-08T13:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to find lost logs from universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214669#M42229</link>
      <description>&lt;P&gt;Please accept the answer.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 15:33:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214669#M42229</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2016-11-08T15:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to find lost logs from universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214670#M42230</link>
      <description>&lt;P&gt;It wasn't available yesterday. Now it is accepted i guess. Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 10:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-lost-logs-from-universal-forwarder/m-p/214670#M42230</guid>
      <dc:creator>ozirus</dc:creator>
      <dc:date>2016-11-09T10:37:02Z</dc:date>
    </item>
  </channel>
</rss>

