<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk No Longer Collecting ANY logs from any hosts? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327800#M60855</link>
    <description>&lt;P&gt;First thing I would check is-  ensure your set up is allowing traffic on port 9997 - from the web console   Settings &amp;gt;Forwarding and Receiving &amp;gt; Configure Receiving  &amp;gt; Add port 9997 &lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 19:04:23 GMT</pubDate>
    <dc:creator>klaxdal</dc:creator>
    <dc:date>2018-03-02T19:04:23Z</dc:date>
    <item>
      <title>Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327799#M60854</link>
      <description>&lt;P&gt;SET UP: splunk v 6.6.4 running Windows 10; &lt;/P&gt;

&lt;P&gt;STUFF I TRIED: Restarted VM, restarted splunk, restarted service on server.&lt;BR /&gt;
Monitoring console shows license is good, disk usage at less than 50%, &lt;BR /&gt;
Health Check: Nothing unexpected.&lt;BR /&gt;
We only have ~28 devices.&lt;BR /&gt;
We use a master-slave license issue. Unsure if the master instance may be running a different version (would that cause this?).&lt;BR /&gt;
Some appliances have a firewall to traverse, others do not: Not getting any logs for anything, so I don't believe it is a firewall issue.&lt;/P&gt;

&lt;P&gt;any guidance is appreciated. &lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327799#M60854</guid>
      <dc:creator>handlin2014</dc:creator>
      <dc:date>2018-03-02T15:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327800#M60855</link>
      <description>&lt;P&gt;First thing I would check is-  ensure your set up is allowing traffic on port 9997 - from the web console   Settings &amp;gt;Forwarding and Receiving &amp;gt; Configure Receiving  &amp;gt; Add port 9997 &lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 19:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327800#M60855</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2018-03-02T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327801#M60856</link>
      <description>&lt;P&gt;Thanks for the quick response...&lt;BR /&gt;
Port 9997 is enabled under Fowarding and Receiving | Configure Receiving | 9997 = enabled.&lt;BR /&gt;
All logs were coming in and then about 2 weeks ago, all logs from all devices just stopped.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 19:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327801#M60856</guid>
      <dc:creator>handlin2014</dc:creator>
      <dc:date>2018-03-02T19:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327802#M60857</link>
      <description>&lt;P&gt;The following can help - &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 02:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327802#M60857</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-03-03T02:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327803#M60858</link>
      <description>&lt;P&gt;hey handlin2014,&lt;/P&gt;

&lt;P&gt;What errors are you getting in internal logs?&lt;BR /&gt;
Check index=_internal on the master for any errors.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 13:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327803#M60858</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-03-05T13:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327804#M60859</link>
      <description>&lt;P&gt;I appreciate it, but no, this isn't what my issue is. &lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 14:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327804#M60859</guid>
      <dc:creator>handlin2014</dc:creator>
      <dc:date>2018-03-05T14:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk No Longer Collecting ANY logs from any hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327805#M60860</link>
      <description>&lt;P&gt;Same problem here, &lt;BR /&gt;
I got logs working for a while and then stops indexing without reason, splunk keep receiving logs so the counter keep increase but last log received is stop to a couple of hours ago, depends when stops.&lt;/P&gt;

&lt;P&gt;I just have 10 mikrotik devices, nothing else. I have the same problem on windows machine, linux and docker running on synology.&lt;BR /&gt;
Checking with wireshark the logs are coming in correctly from the devices.&lt;/P&gt;

&lt;P&gt;I don't know how to resolve, I reinstalled splunk so many times now!!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 12:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-No-Longer-Collecting-ANY-logs-from-any-hosts/m-p/327805#M60860</guid>
      <dc:creator>pixartao</dc:creator>
      <dc:date>2019-08-18T12:45:38Z</dc:date>
    </item>
  </channel>
</rss>

