<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder not sending data to indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311143#M58438</link>
    <description>&lt;P&gt;Hi AB,&lt;BR /&gt;
some questions, to better understand the situation:&lt;/P&gt;

&lt;P&gt;when the file is recreated, it's different, the same or both the possibilities?&lt;/P&gt;

&lt;P&gt;Surely Splunk don't index it when it's the same, but only when updated.&lt;/P&gt;

&lt;P&gt;When you update file, do you modify first chars?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 09:03:45 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-08-31T09:03:45Z</dc:date>
    <item>
      <title>Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311142#M58437</link>
      <description>&lt;P&gt;Please check the splunkd.log&lt;/P&gt;

&lt;P&gt;08-30-2017 21:03:32.004 -0400 INFO TcpOutputProc - Connected to idx=10.100.xxx.1:9997, pset=0, reuse=0.&lt;BR /&gt;
08-30-2017 21:03:32.008 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/searchhistory.log'.&lt;BR /&gt;
08-30-2017 21:03:32.009 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.&lt;BR /&gt;
08-30-2017 21:03:32.011 -0400 INFO WatchedFile - Will begin reading at offset=57592 for file='/opt/splunkforwarder/var/log/splunk/audit.log'.&lt;BR /&gt;
08-30-2017 21:03:32.013 -0400 INFO WatchedFile - Will begin reading at offset=969 for file='/opt/splunkforwarder/var/log/splunk/conf.log'.&lt;BR /&gt;
08-30-2017 21:03:32.014 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/mongod.log'.&lt;BR /&gt;
08-30-2017 21:03:32.016 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/license_usage.log'.&lt;BR /&gt;
08-30-2017 21:03:32.017 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/license_usage_summary.log'.&lt;BR /&gt;
08-30-2017 21:03:32.019 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/remote_searches.log'.&lt;BR /&gt;
08-30-2017 21:03:32.020 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/scheduler.log'.&lt;BR /&gt;
08-30-2017 21:03:32.022 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_ui_access.log'.&lt;BR /&gt;
08-30-2017 21:03:32.024 -0400 INFO WatchedFile - Will begin reading at offset=369 for file='/opt/splunkforwarder/var/log/splunk/splunkd_stderr.log'.&lt;BR /&gt;
08-30-2017 21:03:32.025 -0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_stdout.log'.&lt;BR /&gt;
08-30-2017 21:03:32.102 -0400 INFO WatchedFile - Will begin reading at offset=20365668 for file='/opt/splunkforwarder/var/log/splunk/metrics.log'.&lt;BR /&gt;
08-30-2017 21:14:07.561 -0400 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/scripts/rsda.txt'.&lt;BR /&gt;
08-30-2017 21:29:06.640 -0400 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/scripts/rsda.txt'.&lt;/P&gt;

&lt;P&gt;I need the file /opt/scripts/rsda.txt to be indexed , this is file is recreated every 15 mins....&lt;BR /&gt;
but this is not coming to indexer&lt;BR /&gt;
both UF and Indexer are in Linux, ping is working both ways....&lt;/P&gt;

&lt;P&gt;I have searched , there are so many posts but none is addressing this problem..&lt;/P&gt;

&lt;P&gt;Thank you&lt;BR /&gt;
AB&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311142#M58437</guid>
      <dc:creator>722624</dc:creator>
      <dc:date>2020-09-29T15:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311143#M58438</link>
      <description>&lt;P&gt;Hi AB,&lt;BR /&gt;
some questions, to better understand the situation:&lt;/P&gt;

&lt;P&gt;when the file is recreated, it's different, the same or both the possibilities?&lt;/P&gt;

&lt;P&gt;Surely Splunk don't index it when it's the same, but only when updated.&lt;/P&gt;

&lt;P&gt;When you update file, do you modify first chars?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 09:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311143#M58438</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-31T09:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311144#M58439</link>
      <description>&lt;P&gt;Hello Giuseppe....&lt;BR /&gt;
the file is created every 15 mins with same file name,,,,but with different content ,&lt;BR /&gt;
I have total 15 hosts, same configuration , same OS, same UF...13 hosts are sending but 2 hosts are not sending...&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 09:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311144#M58439</guid>
      <dc:creator>722624</dc:creator>
      <dc:date>2017-08-31T09:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311145#M58440</link>
      <description>&lt;P&gt;ok for different content, but the first 256 chars hare different or the same?&lt;/P&gt;

&lt;P&gt;When you say that the only two servers aren't sending logs, do you mean that the problem is only on two UF and correctly runs on the other 13?&lt;BR /&gt;
If yes, delete the first question.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 09:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311145#M58440</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-31T09:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311146#M58441</link>
      <description>&lt;P&gt;Hello Giuseppe,&lt;BR /&gt;
Thanks for quick response&lt;BR /&gt;
Yes..first 250 chars are also different&lt;BR /&gt;
We have same version of UF installed on each of our 15 hosts...13 hosts are sending data to indexer..but  2 hosts are not sending the data&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 09:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311146#M58441</guid>
      <dc:creator>722624</dc:creator>
      <dc:date>2017-08-31T09:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311147#M58442</link>
      <description>&lt;P&gt;Yes, the problem that you don't index updates there is only on two Forwarders or in all Forwarders?&lt;BR /&gt;
if the first, you have to check if the two Forwarders send other logs to Indexer ( &lt;CODE&gt;index=_internal host=your_host1 OR host=your_host2&lt;/CODE&gt; ).&lt;BR /&gt;
If the second, it's a different problem.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 09:54:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311147#M58442</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-31T09:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311148#M58443</link>
      <description>&lt;P&gt;only two forwrarders  are not sending... index=_internal host=your_host1 ...is not giving any data&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311148#M58443</guid>
      <dc:creator>722624</dc:creator>
      <dc:date>2020-09-29T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311149#M58444</link>
      <description>&lt;P&gt;This means that the problem isn't in the ingestion of the variation of the file, te problem in in connection!&lt;/P&gt;

&lt;P&gt;at first check if firewalls rules are open, using telnet IP_Indexer 9997&lt;/P&gt;

&lt;P&gt;if ok, check hostname in $SPLUNK_HOME/etc/system/local/inputs.conf and $SPLUNK_HOME/etc/system/local/server.conf (beware if you have the same hostname of another forwarder sometimes it happens!)&lt;/P&gt;

&lt;P&gt;if ok, check if outputs.conf is correctly configurated (usually is in $SPLUNK_HOME/etc/system/local/ or in a dedicated App): you must have something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group
[tcpout:default-autolb-group]
server = IP_Indexer:9997
disabled=false
[tcpout-server://IP_Indexer:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;otherwise see at &lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.6.3/Forwarder/Troubleshoottheuniversalforwarder" target="_blank"&gt;http://docs.splunk.com/Documentation/Forwarder/6.6.3/Forwarder/Troubleshoottheuniversalforwarder&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311149#M58444</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T15:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311150#M58445</link>
      <description>&lt;P&gt;ok, so what did it what fixed it? this is so frustrating finding unanswered threads, not your fault, just the Splunk Documentation is so lacking and here I am three years later with a very similar issue&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 23:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311150#M58445</guid>
      <dc:creator>muszyngr</dc:creator>
      <dc:date>2020-03-09T23:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not sending data to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311151#M58446</link>
      <description>&lt;P&gt;You need to modify &lt;CODE&gt;CHECK_METHOD&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; to &lt;CODE&gt;modtime&lt;/CODE&gt; (checks only modification time of file):&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?utm_source=answers&amp;amp;utm_medium=in-answer&amp;amp;utm_term=props.conf&amp;amp;utm_campaign=refdoc#File_checksum_configuration"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?utm_source=answers&amp;amp;utm_medium=in-answer&amp;amp;utm_term=props.conf&amp;amp;utm_campaign=refdoc#File_checksum_configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 04:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-sending-data-to-indexer/m-p/311151#M58446</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-10T04:40:40Z</dc:date>
    </item>
  </channel>
</rss>

