<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252491#M48550</link>
    <description>&lt;P&gt;thanks Giuseppe, Actually I am new to this environment, the person who had built the entire splunk environment had left the organization and there is no document on how they have configured it. &lt;/P&gt;

&lt;P&gt;Ours is Distributed Splunk Environment, where we have 4 search head two are in clustered and other are independent, one file sharing pool, 5 indexer, License/deployment manager and two heavy forwarder with version 6.2.1. &lt;/P&gt;

&lt;P&gt;As per the architecture diagram, data's from UF are forwarded to Indexers directly and only the syslogs are forwarded to the HF using the TCP/UDP port 514. &lt;/P&gt;

&lt;P&gt;From search portal, by executing this query &lt;STRONG&gt;host=XXXX index=Symantec&lt;/STRONG&gt;, I could see the data and the source is pointed to this path &lt;STRONG&gt;/opt/syslogs/Symantec/Symantecserver/server name/servername.log&lt;/STRONG&gt; and the same path is configured in the HF inputs.conf. &lt;/P&gt;

&lt;P&gt;HF input stanza &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/syslogs/symantec/SymantecServer/...]
 whitelist = \.log
 index = Symantec 
 sourcetype = sep  
 host_segment = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But currently under this path opt/syslogs/Symantec/Symantecserver/server name / there is no logs getting in. I am not sure how it got broken and currently the user has complained that he is not getting the data to analysis.  So kindly tell me how to trouble shoot this issue. &lt;/P&gt;</description>
    <pubDate>Fri, 15 Jul 2016 11:04:01 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2016-07-15T11:04:01Z</dc:date>
    <item>
      <title>How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252481#M48540</link>
      <description>&lt;P&gt;Currently we have an issue in getting the data into the heavy forwarder. We could see that below stanza is configured in the heavy forwarders, When checked under the path as mentioned in the stanza, we could not see logs getting into the server from the source.&lt;/P&gt;

&lt;P&gt;Heavy forwarder stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/syslogs/symantec/SymantecServer/...]
whitelist = \.log
index = Symantec 
sourcetype = sep  
host_segment = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Indexer inputs.conf stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://hostname.com:8501]
connection_host = dns
index = Symantec
source = hostname.com:8501
sourcetype = sep
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Source where Splunk monitors the logs from the heavy forwarder. Currently there are no logs under this folder:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/opt/syslogs/symantec/SymantecServer/hostname/hostname.log"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunkd.log from the Universal Forwarder server version 6.2 &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-22-2016 01:31:13.857 -0400 ERROR TcpOutputFd - Connection to host=x.x.x.x:9997 failed
06-22-2016 01:31:43.615 -0400 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Initially the logs were getting into this heavy forwarder server from the universal forwarder server, but somehow this got broken. Kindly guide us in fixing this issue. &lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 18:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252481#M48540</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-11T18:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252482#M48541</link>
      <description>&lt;P&gt;What is in your outputs.conf on the HF?&lt;/P&gt;

&lt;P&gt;Why are you using UDP inputs on your indexer? Is your HF sending the data to the indexer via UDP instead of using port 9997 on the indexer (as is most usually the case)?&lt;/P&gt;

&lt;P&gt;Is the indexer RECEIVING logs from another source and forwarding on to the indexers, or just using a HF as the forwarder on a host because you want some of the functionality of the HF instead of a UF?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 20:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252482#M48541</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2016-07-11T20:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252483#M48542</link>
      <description>&lt;P&gt;You don't need to use UDP on the indexer, the HF sends its logs to the indexer.&lt;BR /&gt;
Check if your Indexer receives logs from you HF, maybe the problem is in HF output.conf or Indexer receiving.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 07:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252483#M48542</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-12T07:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252484#M48543</link>
      <description>&lt;P&gt;Shouldn't you be listening on port 9997 on your indexer?&lt;/P&gt;

&lt;P&gt;Unless your outputs in your HF are doing raw udp transfers (for some bizarre firewall reason perhaps?) you have your hf incorrectly configured.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 10:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252484#M48543</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2016-07-12T10:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252485#M48544</link>
      <description>&lt;P&gt;thanks for getting into this..&lt;/P&gt;

&lt;P&gt;What is in your outputs. Conf on the HF? &lt;BR /&gt;
currently we could see &lt;STRONG&gt;four outputs.conf file&lt;/STRONG&gt; present in the HF. &lt;/P&gt;

&lt;P&gt;a) &lt;STRONG&gt;/opt/splunk/etc/apps/Admin-hvy_forwarders/default/outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
   stanza &lt;BR /&gt;
   [tcpout]&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
forwardedindex.filter.disable = true&lt;BR /&gt;
forceTimebasedAutoLB = true&lt;/P&gt;

&lt;P&gt;b) &lt;STRONG&gt;/opt/splunk/etc/apps/ADMIN-all_fwd_outputs/default/outputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = all_indexers&lt;BR /&gt;
maxQueueSize = 1GB&lt;/P&gt;

&lt;P&gt;[tcpout:all_indexers]&lt;BR /&gt;
server = host1.com:9997,host2.com:9997,host3.com:9997,host4.com:9997,host5:9997&lt;BR /&gt;
autoLB = true&lt;/P&gt;

&lt;P&gt;c) &lt;STRONG&gt;/opt/splunk/etc/apps/all_fwd_outputs/local/outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
     [tcpout]&lt;BR /&gt;
defaultGroup = all_indexers&lt;/P&gt;

&lt;P&gt;[tcpout:all_indexers]&lt;BR /&gt;
server = host1.com:9997,host2.com:9997,host3.com:9997,host4.com:9997,host5:9997&lt;BR /&gt;
autoLB = true&lt;/P&gt;

&lt;P&gt;d) &lt;STRONG&gt;/opt/splunk/etc/system/local/outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
  [tcpout]&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
forwardedindex.filter.disable = true&lt;/P&gt;

&lt;P&gt;[tcpout:all_indexers]&lt;BR /&gt;
server = host1.com:9997,host2.com:9997,host3.com:9997,host4.com:9997,host5:9997&lt;BR /&gt;
autoLB = true&lt;/P&gt;

&lt;P&gt;Which one we need to consider on this four outputs.conf files.&lt;/P&gt;

&lt;P&gt;2) Why are you using UDP inputs on your indexer? Is your HF sending the data to the indexer via UDP instead of using port 9997 on the indexer (as is most usually the case)?&lt;/P&gt;

&lt;P&gt;I am not sure why are they using UDP port in indexer. how to find that HF sending the data to the indexer via UDP port ? &lt;/P&gt;

&lt;P&gt;3)  Is the indexer RECEIVING logs from another source and forwarding on to the indexers, or just using a HF as the forwarder on a host because you want some of the functionality of the HF instead of a UF?&lt;/P&gt;

&lt;P&gt;No, as per the architecture we have HF for load balancer  and in this case data are pulled from the Universal forwarder &lt;STRONG&gt;"Source where the Symantec logs are getting generated sent via UF to Heavy Forwarder servers" from there to distributed indexer servers&lt;/STRONG&gt;.  &lt;/P&gt;

&lt;P&gt;kindly guide us in fixing this issue. Thanks in Advance &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252485#M48544</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T10:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252486#M48545</link>
      <description>&lt;P&gt;thanks Giuseppe, actually logs are getting in to the &lt;STRONG&gt;Heavy Forwarder from the UF agent machine&lt;/STRONG&gt;. Below is the heavy forwarder stanza from where the splunk is monitoring the Symantec logs then forwards to the Indexer. In my case the data are coming to the HF. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/syslogs/symantec/SymantecServer/...]
 whitelist = \.log
 index = Symantec 
 sourcetype = sep  
host_segment = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;when checked in this path we did not find any logs folder was empty in HF server&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;opt/syslogs/symantec/SymantecServer/hostname/ ---&amp;gt; is empty&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;Checked in the host where UF is configured and found splunk UF agent is running fine. Kindly guide us in getting this fixed. thanks advance &lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 18:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252486#M48545</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-12T18:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252487#M48546</link>
      <description>&lt;P&gt;thank Lucas, for your inputs on this issue. I have pasted the outputs.conf stanza in above comment. Kindly guide me to get this fix. thanks Advance. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 18:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252487#M48546</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-12T18:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252488#M48547</link>
      <description>&lt;P&gt;I agree with @cusello. In addition to that, you don't need ... in stanza if you want to monitor everything under particular folder. You can update the stanza as &lt;BR /&gt;
[monitor:///opt/syslogs/symantec/SymantecServer/]&lt;/P&gt;

&lt;P&gt;Also check the  outputs.conf is correctly configured to forward to indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 18:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252488#M48547</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2016-07-12T18:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252489#M48548</link>
      <description>&lt;P&gt;1) Your all_indexers group seems to be configured fine, so that should be working. I am wondering why you don't seem to have a server config item for the hvy_forwarders outputs.conf file. It should be like the UF outputs.conf files in that regard. Your heavy forwarder probably using the other outputs.conf files as well, so that might not be important. On my servers I have a configuration that goes to HFs that are separate from the UF configs and are deployed by the deployment server. In your case, it looks like the HF has all these configs, so that should not be a problem, since they don't have things that seem to be inconsistent with one another&lt;/P&gt;

&lt;P&gt;2) UDP is bad for sending things into the indexers because there is no guarantee that the data make is in. The data just gets thrown over the fence and you have to hope there is someone on the other side to catch it and deliver it properly. From the data in the outputs .conf files, it doesn't appear that UDP is being used to sent the data to the indexers. The indexers would have to have an input set up for that port it would be using in order to catch the data.&lt;/P&gt;

&lt;P&gt;3) So from what you are saying, it appears that the data from Symantec is coming into the HF by UDP (which would be equivalent to what syslog does - on port 514 by default). I can see this as a way to get the logs into Splunk, and it's similar to what we used to do. Now we use rsyslog on a server with a HF and the syslog server receives the syslog data, puts it into files, which the HF then forwards to the indexers. The advantage to this method is that the syslog server is very light weight and it can be restarted very quickly, while the HF can take a bit of time (dozens to hundreds of seconds) to restart, causing more data loss than the sub-second restart of the rsyslog server. But that is syslog, and not port 8501. I'm still not sure why you would want the indexers to listen on port 8501 if the HF is doing the listening. It will forward the data on to the indexers over port 9997. Perhaps that is where some confusion exists.&lt;/P&gt;

&lt;P&gt;Why did you switch from the UF to UDP for sending the data into the indexers? Perhaps I don't understand exactly what you mean by that in your original post. If it was working, that would have been my preferred method to get the data into Splunk. UDP is always less reliable (though faster) than TCP.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252489#M48548</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2020-09-29T10:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252490#M48549</link>
      <description>&lt;P&gt;sorry but I don't understand: if you receive logs from UF and then forward them to the indexers you don't need to monitor any file on the HF.&lt;BR /&gt;
You have to monitor files on HF only if another agent (not Splunk UF) writes them on the HF.&lt;BR /&gt;
Everyway, check if the indexers receives logs from the HF (index=_internal host=HF) and from the UF.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 07:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252490#M48549</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-13T07:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252491#M48550</link>
      <description>&lt;P&gt;thanks Giuseppe, Actually I am new to this environment, the person who had built the entire splunk environment had left the organization and there is no document on how they have configured it. &lt;/P&gt;

&lt;P&gt;Ours is Distributed Splunk Environment, where we have 4 search head two are in clustered and other are independent, one file sharing pool, 5 indexer, License/deployment manager and two heavy forwarder with version 6.2.1. &lt;/P&gt;

&lt;P&gt;As per the architecture diagram, data's from UF are forwarded to Indexers directly and only the syslogs are forwarded to the HF using the TCP/UDP port 514. &lt;/P&gt;

&lt;P&gt;From search portal, by executing this query &lt;STRONG&gt;host=XXXX index=Symantec&lt;/STRONG&gt;, I could see the data and the source is pointed to this path &lt;STRONG&gt;/opt/syslogs/Symantec/Symantecserver/server name/servername.log&lt;/STRONG&gt; and the same path is configured in the HF inputs.conf. &lt;/P&gt;

&lt;P&gt;HF input stanza &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/syslogs/symantec/SymantecServer/...]
 whitelist = \.log
 index = Symantec 
 sourcetype = sep  
 host_segment = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But currently under this path opt/syslogs/Symantec/Symantecserver/server name / there is no logs getting in. I am not sure how it got broken and currently the user has complained that he is not getting the data to analysis.  So kindly tell me how to trouble shoot this issue. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 11:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252491#M48550</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-15T11:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252492#M48551</link>
      <description>&lt;P&gt;thanks cpetterborg, Ours is a Distributed Splunk Environment, where we have 4 search head two are in clustered and other are independent, one file sharing pool, 5 indexer, License/deployment manager and two heavy forwarder with version 6.2.1.&lt;/P&gt;

&lt;P&gt;As per the architecture diagram, data's from UF are forwarded to Indexers directly and only the syslogs are forwarded to the HF using the TCP/UDP port 514.  &lt;/P&gt;

&lt;P&gt;But when searched in the portal by executing this query host=XXXX index=Symantec, I could see the data and the source is pointed to this path /opt/syslogs/Symantec/Symantecserver/server name/servername.log and the same path is configured in the HF inputs.conf.&lt;/P&gt;

&lt;P&gt;I am getting confused with lots of inputs.conf and outputs.conf in HF/UF/Indexers. Kindly let know how to figure out which configuration files are used to send the data.&lt;BR /&gt;&lt;BR /&gt;
thanks in advance.. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 12:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252492#M48551</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-15T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252493#M48552</link>
      <description>&lt;P&gt;This stanza was working in the past?&lt;BR /&gt;
I see that in the white list line there should be a backslash before the dot.&lt;/P&gt;

&lt;P&gt;if don't run see using tcpdump if logs arrives to the HF.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 14:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252493#M48552</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-15T14:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252494#M48553</link>
      <description>&lt;P&gt;thanks Giuseppe. yes we have found that the data are getting into the HF but its pointing to some other indexer and I am not sure how this got changed.&lt;/P&gt;

&lt;P&gt;Currently the data's  from the Symantec servers are getting in to this path /opt/syslogs/generic/hostname/SymantecServer.log in HF and but  pointing to different index name =unix_srvs and source type=syslog. &lt;/P&gt;

&lt;P&gt;Inputs.conf Stanza details&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/syslogs/generic/.../*.log]
sourcetype = syslog
host_segment = 4
blacklist = dxxx*ltm*
index=unix_srvs 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;now its clear that the data are getting  into HF but in different location, different indexer, source type, so how to fix this issue. &lt;BR /&gt;
By changing the inputs.conf stanza alone will fix the issue or before doing this we should make sure that data are getting in to the correct path in HF before splunk monitors the logs.  &lt;/P&gt;

&lt;P&gt;correct path = opt/syslogs/symantec/Symantecserver/xxxx/.log&lt;BR /&gt;
index =Symantec&lt;BR /&gt;
sourcetype =sym&lt;/P&gt;

&lt;P&gt;kindly guide us how to proceed to fix the issue. &lt;BR /&gt;
thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 10:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252494#M48553</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-18T10:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252495#M48554</link>
      <description>&lt;P&gt;verify the exact position of each log using a search on linux of the directory you have in the monitor line:&lt;BR /&gt;
e.g.: ls -al /opt/syslogs/symantec/Symantecserver/&lt;EM&gt;/&lt;/EM&gt;.log&lt;BR /&gt;
(Note the star before .log, this isn't a regex)&lt;BR /&gt;
and then build a stanza for each one with the path you verified, the correct index and sourcetype.&lt;BR /&gt;
verify also that there aren't wrong files, if there are use blacklist.&lt;BR /&gt;
If you need more help ask!&lt;BR /&gt;
bye.&lt;BR /&gt;
Giuseppe&lt;BR /&gt;
(if you like accept my answer)&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 11:27:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252495#M48554</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-18T11:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252496#M48555</link>
      <description>&lt;P&gt;thanks cusello. But I have question, how can I create a stanza to monitor the path when there is no data getting into this path &lt;STRONG&gt;/opt/syslogs/Symantec/Symantecserver/hostname/.log&lt;/STRONG&gt; ---&amp;gt; zero logs. &lt;BR /&gt;
As I told you, that  logs are getting  into   &lt;STRONG&gt;/opt/syslogs/generic/hostname/SymantecServer.log&lt;/STRONG&gt; and its pointed to this index=unix_srvs and sourcetype as syslogs. which is not correct index and sourcetype. It should be index=Symantec and sourcetype = sym. &lt;/P&gt;

&lt;P&gt;kindly guide me on this.  &lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 14:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252496#M48555</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-18T14:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252497#M48556</link>
      <description>&lt;P&gt;did you used /opt/syslogs/Symantec/Symantecserver/hostname/*.log or /opt/syslogs/Symantec/Symantecserver/hostname/.log?&lt;BR /&gt;
without star it doesn't run!&lt;BR /&gt;
try to search files in your CLI interface, when you find the files with the ls -la command, use the same path in the monitor command.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 15:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252497#M48556</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-18T15:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252498#M48557</link>
      <description>&lt;P&gt;thanks Cusello, I had tried to search the same way as you had  suggested in the search portal&lt;BR /&gt;
but no result.    &lt;/P&gt;

&lt;P&gt;query details - &lt;BR /&gt;
source= "/opt/syslogs/Symantec/Symantecserver/hostname/*.log" &lt;/P&gt;

&lt;P&gt;similarly when searched same thing in CLI using the command ls -la there were no hidden files present in the path /opt/syslogs/Symantec/symantecserver/hostname/....&lt;/P&gt;

&lt;P&gt;kindly guide me on this &lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 17:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252498#M48557</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-18T17:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252499#M48558</link>
      <description>&lt;P&gt;verify the path of the monitored files with the command ls -la:&lt;/P&gt;

&lt;P&gt;if you have files, for example in /tmp/test &lt;BR /&gt;
use &lt;CODE&gt;ls -la /tmp/test&lt;/CODE&gt;&lt;BR /&gt;
you should have some files like ppp.log, qqq.log ...&lt;BR /&gt;
to this point you can set your inputs.conf stanza&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///tmp/test/*.log]
index = index_test
sourcetype = sourcetype_test
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;after you can search them with&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index_test
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 06:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252499#M48558</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-07-19T06:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why we are unable to get data into our heavy forwarder and then to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252500#M48559</link>
      <description>&lt;P&gt;Thanks Giuseppe,  We have tested the above command under path from where the splunk reads the file and forwards to HF. As I told you earlier there is no data under this path from the source system (host machine).&lt;/P&gt;

&lt;P&gt;[root@splunkhvy hostname]# pwd&lt;BR /&gt;
/opt/syslogs/symantec/SymantecServer/hostname&lt;BR /&gt;
[root@splunkhvy hostname]# ls -la&lt;BR /&gt;
total 8&lt;BR /&gt;
drwx------ 2 root root 4096 Apr 22 05:27 .&lt;BR /&gt;
drwx------ 5 root root 4096 Apr 22 05:27 ..&lt;/P&gt;

&lt;P&gt;As you know , we are getting the data from the same host under this path&lt;/P&gt;

&lt;P&gt;[root@splunkhvy syslogs]# cd generic/hostname/&lt;BR /&gt;
[root@splunkhvy hostname]# pwd&lt;BR /&gt;
/opt/syslogs/generic/hostname&lt;BR /&gt;
[root@splunkhvy hostname]# ls -ltr&lt;BR /&gt;
total 15683036&lt;BR /&gt;
-rw------- 1 root root 16059374206 Jul 25 06:25 SymantecServer.log&lt;BR /&gt;
[root@splunkhvy hostname]#&lt;/P&gt;

&lt;P&gt;Now we have doubt whether the hostname.log is getting generated from the source system or not ? As we are unable to see the data from the Symantec source system with the file name hostname.log. &lt;/P&gt;

&lt;P&gt;Suppose if we want to re-install the universal and configure new agent, then what are the steps we should follow to get the data from UF to HF then to Indexer.&lt;/P&gt;

&lt;P&gt;thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 10:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-we-are-unable-to-get-data-into-our-heavy/m-p/252500#M48559</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-25T10:37:29Z</dc:date>
    </item>
  </channel>
</rss>

