<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder not sending data to indexer after successful connection in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250843#M48288</link>
    <description>&lt;P&gt;You have a linebreaking/merging problem or a timestamping problem (the former often causes the latter).  We need to see a few sample log events and your inputs.conf and props.conf files.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jul 2016 13:16:03 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-07-10T13:16:03Z</dc:date>
    <item>
      <title>Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250841#M48286</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
 I have a setup that consists of a Search Head and 2 indexers in a cluster. I also use a self signed SSL certificate between the indexers and my universal forwarders. &lt;/P&gt;

&lt;P&gt;For some reason, my UF is able to connect to the indexers, but no data is sent. &lt;BR /&gt;
07-09-2016 00:21:15.670 +0000 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;My test logs directly on the indexers were sent to the search head without issue. &lt;/LI&gt;
&lt;LI&gt;running splunk list monitor on the UF lists all the logs I want to monitor&lt;/LI&gt;
&lt;LI&gt;No errors in splunkd.log on the UF that I can see, just the usual warnings I get in my duplicate setup in another enviornment that IS working. &lt;/LI&gt;
&lt;LI&gt;No errors in metrics.log on the UF either. &lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;On the Indexer is this warning: &lt;/P&gt;

&lt;P&gt;WARN  DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Fri Jul  8 20:30:38 2016). Context: source::\&lt;REDACTED&gt;\s$\Logs\service.log|host::&lt;REDACTED&gt;|Service Logs|174315&lt;/REDACTED&gt;&lt;/REDACTED&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;What else can I test to pinpoint my issue?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jul 2016 00:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250841#M48286</guid>
      <dc:creator>RecoMark0</dc:creator>
      <dc:date>2016-07-09T00:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250842#M48287</link>
      <description>&lt;P&gt;It's possible that the timestamp recognition is not working as expected and the events are indexed with an old timestamp. &lt;BR /&gt;
Have you tried setting the time range to 'all time' and see if there are any events from this forwarder?&lt;/P&gt;

&lt;P&gt;Try &lt;CODE&gt;| metadata type=hosts index=*&lt;/CODE&gt; to see if the host is connected&lt;/P&gt;

&lt;P&gt;Also have a look at &lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 09 Jul 2016 02:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250842#M48287</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-07-09T02:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250843#M48288</link>
      <description>&lt;P&gt;You have a linebreaking/merging problem or a timestamping problem (the former often causes the latter).  We need to see a few sample log events and your inputs.conf and props.conf files.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 13:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250843#M48288</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-10T13:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250844#M48289</link>
      <description>&lt;P&gt;The "official" documentation to debug such a case at &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata#Are_you_using_forwarders.3"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 14:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250844#M48289</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-10T14:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250845#M48290</link>
      <description>&lt;P&gt;Sigh, I forgot to add the index my inputs.conf was going to, to the admin role "indexes searched by default". Sorry for wasting everyone's time! Rookie mistake. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 15:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250845#M48290</guid>
      <dc:creator>RecoMark0</dc:creator>
      <dc:date>2016-07-11T15:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data to indexer after successful connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250846#M48291</link>
      <description>&lt;P&gt;It's all good - we all make all sorts of mistakes...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 15:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-to-indexer-after-successful/m-p/250846#M48291</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-11T15:16:41Z</dc:date>
    </item>
  </channel>
</rss>

