<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New logs not feeding into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329621#M61128</link>
    <description>&lt;P&gt;Splunk is a different thing than rsyslog. &lt;/P&gt;

&lt;P&gt;rsyslog catches syslog and writes to a file (or does other tricks with it), where a Splunk forwarder then monitors that file....&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;can you clarify your set up?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2017 12:56:38 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2017-10-30T12:56:38Z</dc:date>
    <item>
      <title>New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329617#M61124</link>
      <description>&lt;P&gt;I have a Red Hat server running rsyslog. Everything is logging but 1 log is not feeding into Splunk. The rsyslog.conf file is configured properly and the log is populating under /opt/remote_logs/. Any ideas?&lt;/P&gt;

&lt;P&gt;From duplicate post:&lt;BR /&gt;
I am running a Red Hat server with rsyslog. I have a ldap server pushing logs to rsyslog in a lab environment that is mirrored to the production server. It is logging and feeding into Splunk. When I switch over to the production server, it will not log in rsyslog. The rsyslog.conf is properly configured and I have confirmed the the production ldap server is configured properly too. Any ideas? &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:44:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329617#M61124</guid>
      <dc:creator>andsmith2</dc:creator>
      <dc:date>2017-10-30T12:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329618#M61125</link>
      <description>&lt;P&gt;Start by confirming your inputs are working by using &lt;CODE&gt;./splunk list inputstatus&lt;/CODE&gt; on the forwarder and look for the status of that particular input, or by checking &lt;CODE&gt;index=_internal source=*splunkd.log tailreader&lt;/CODE&gt; and look for your filename. &lt;/P&gt;

&lt;P&gt;If your inputs are correct then the tailreader should have found that file and it will tell you what it has done with it thus far. &lt;/P&gt;

&lt;P&gt;Also, you could check &lt;CODE&gt;index=* source=yourFileName&lt;/CODE&gt; ALLTIME, to ensure you aren't dealing with wacky timestamping. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329618#M61125</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-30T12:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329619#M61126</link>
      <description>&lt;P&gt;Is your universal forwarder configured correctly?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329619#M61126</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-10-30T12:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329620#M61127</link>
      <description>&lt;P&gt;Not using a universal forwarder. LDAP is forwarding logs to Splunk rsyslog. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329620#M61127</guid>
      <dc:creator>andsmith2</dc:creator>
      <dc:date>2017-10-30T12:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329621#M61128</link>
      <description>&lt;P&gt;Splunk is a different thing than rsyslog. &lt;/P&gt;

&lt;P&gt;rsyslog catches syslog and writes to a file (or does other tricks with it), where a Splunk forwarder then monitors that file....&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;can you clarify your set up?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329621#M61128</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-30T12:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329622#M61129</link>
      <description>&lt;P&gt;I have a Red Hat server dedicated to Splunk. It is running rsyslog. All of my host that can not use a universal forwarder, send their logs to rsyslog and then get feed in Splunk. Everything is logging and writing to file but only 1 is not view-able on the Search Head.  &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 13:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329622#M61129</guid>
      <dc:creator>andsmith2</dc:creator>
      <dc:date>2017-10-30T13:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329623#M61130</link>
      <description>&lt;P&gt;Ok, have you set up a monitor in splunk to go get that file?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Monitorfilesanddirectories"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 13:47:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329623#M61130</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-30T13:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329624#M61131</link>
      <description>&lt;P&gt;Thank you. I got it working. I forgot the the monitors were in inputs.conf on my deployment server. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 14:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329624#M61131</guid>
      <dc:creator>andsmith2</dc:creator>
      <dc:date>2017-10-30T14:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329625#M61132</link>
      <description>&lt;P&gt;nice! be sure to post an answer and accept it so that future splunkers can see what you checked!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 14:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329625#M61132</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-30T14:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: New logs not feeding into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329626#M61133</link>
      <description>&lt;P&gt;New sourcetypes on you syslog server need to have the monitor added to your inputs.conf. For example, I added new logging from my netscalers, so I updated my rsyslog.conf on the syslog server. I then had to update my inputs.conf for syslog on my deployment server and add the monitor for this new sourcetype.  &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 14:45:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-logs-not-feeding-into-Splunk/m-p/329626#M61133</guid>
      <dc:creator>andsmith2</dc:creator>
      <dc:date>2017-10-30T14:45:27Z</dc:date>
    </item>
  </channel>
</rss>

