<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not receiving logs from Syslog Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323352#M60221</link>
    <description>&lt;P&gt;There are only INFO messages. &lt;/P&gt;

&lt;P&gt;Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.&lt;/P&gt;

&lt;P&gt;Does restarting the U.F or &lt;CODE&gt;splunk  reload deploy-server&lt;/CODE&gt; both required to apply config settings on U.F ?&lt;/P&gt;

&lt;P&gt;Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings--&amp;gt;Server Settings--&amp;gt; Deployment Client, it shows nothing at all. Any reason why ?&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 01:16:44 GMT</pubDate>
    <dc:creator>damode</dc:creator>
    <dc:date>2018-02-27T01:16:44Z</dc:date>
    <item>
      <title>Not receiving logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323350#M60219</link>
      <description>&lt;P&gt;I have set up a universal forwarder to read logs from kiwi syslog server.&lt;BR /&gt;
Universal Forwarder is set to forward logs to the Indexer via Heavy Forwarder.&lt;BR /&gt;
I have also set  up the Heavy Forwarder as deployment server.&lt;BR /&gt;
I have deployed the following inputs.conf to the U.F by deploying an app from the deployment server.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Program Files (x86)\Syslogd\Logs\x.x.x.x\log*.txt]
index = main
sourcetype = syslog
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;With all the above settings, I still cant see any logs on the Indexer.&lt;BR /&gt;
I have confirmed following things already,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;U.F has the right privilege to read logs from syslog's log folder.&lt;/LI&gt;
&lt;LI&gt;network connection established between Syslog Server and H.F on H.F's port 9997 and 8089.&lt;/LI&gt;
&lt;LI&gt;receiving port 9997 on Indexer enabled.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;splunk btool inputs list monitor command also does not work on the U.F&lt;BR /&gt;
Please help me troubleshoot this. &lt;BR /&gt;
Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 00:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323350#M60219</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2018-02-27T00:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323351#M60220</link>
      <description>&lt;P&gt;Any messages in the splunkd.log file on the universal forwarder? It would be in Splunk_home\var\log\splunk\splunkd.log&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 00:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323351#M60220</guid>
      <dc:creator>stefanhutchison</dc:creator>
      <dc:date>2018-02-27T00:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323352#M60221</link>
      <description>&lt;P&gt;There are only INFO messages. &lt;/P&gt;

&lt;P&gt;Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.&lt;/P&gt;

&lt;P&gt;Does restarting the U.F or &lt;CODE&gt;splunk  reload deploy-server&lt;/CODE&gt; both required to apply config settings on U.F ?&lt;/P&gt;

&lt;P&gt;Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings--&amp;gt;Server Settings--&amp;gt; Deployment Client, it shows nothing at all. Any reason why ?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 01:16:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-logs-from-Syslog-Server/m-p/323352#M60221</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2018-02-27T01:16:44Z</dc:date>
    </item>
  </channel>
</rss>

