<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why did Splunk stop collecting syslog logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379771#M68600</link>
    <description>&lt;P&gt;Are you seeing errors at index=_internal source splunkd?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Sep 2018 10:45:38 GMT</pubDate>
    <dc:creator>dauren_akilbeko</dc:creator>
    <dc:date>2018-09-20T10:45:38Z</dc:date>
    <item>
      <title>Why did Splunk stop collecting syslog logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379770#M68599</link>
      <description>&lt;P&gt;I installed Splunk last week, and I'm only collecting data (syslog) from one source.&lt;/P&gt;

&lt;P&gt;Data stopped being collected this morning. I use Wireshark on the source server and Splunk, and I see that syslog are coming and going, but I don't see logs in Splunk. Latest event 3 hours ago.&lt;/P&gt;

&lt;P&gt;License: Trial license group&lt;BR /&gt;
License expiration Nov 17, 2018 4:04:30 PM&lt;BR /&gt;&lt;BR /&gt;
Licensed daily volume 500 MB&lt;BR /&gt;&lt;BR /&gt;
Volume used today 121 MB (24.135% of quota)&lt;BR /&gt;&lt;BR /&gt;
OS Windows 10 (Microsoft Windows [Version 10.0.16299.15])&lt;BR /&gt;
SPLUNK Version:7.1.3 Build:51d9cac7b837&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 09:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379770#M68599</guid>
      <dc:creator>lorder</dc:creator>
      <dc:date>2018-09-20T09:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Splunk stop collecting syslog logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379771#M68600</link>
      <description>&lt;P&gt;Are you seeing errors at index=_internal source splunkd?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 10:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379771#M68600</guid>
      <dc:creator>dauren_akilbeko</dc:creator>
      <dc:date>2018-09-20T10:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Splunk stop collecting syslog logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379772#M68601</link>
      <description>&lt;P&gt;You should read or watch this excellent session from .conf 2017 - it was a very well attended session. This will give you a best practice syslog server to collect the logs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://conf.splunk.com/sessions/2017-sessions.html#search=critical%20syslog%20tricks&amp;amp;"&gt;http://conf.splunk.com/sessions/2017-sessions.html#search=critical%20syslog%20tricks&amp;amp;&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 17:52:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379772#M68601</guid>
      <dc:creator>JDukeSplunk</dc:creator>
      <dc:date>2018-09-20T17:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Splunk stop collecting syslog logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379773#M68602</link>
      <description>&lt;P&gt;hi @lorder,&lt;/P&gt;

&lt;P&gt;Could you give us some more context on this issue? For instance, as @dauren_akilbekov said, have you documented any errors that you could post? The more information you provide the community, the better chance you have of getting your question answered.&lt;/P&gt;

&lt;P&gt;Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 20:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379773#M68602</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-20T20:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Splunk stop collecting syslog logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379774#M68603</link>
      <description>&lt;P&gt;I use "index=_internal log_level=ERROR" and last eerors is:&lt;/P&gt;

&lt;P&gt;09-20-2018 16:40:21.585 +0500 ERROR KVStoreBulletinBoardManager - KV Store changed status to failed. KVStore process terminated.&lt;/P&gt;

&lt;P&gt;09-20-2018 16:40:21.584 +0500 ERROR KVStoreBulletinBoardManager - KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.&lt;/P&gt;

&lt;P&gt;09-20-2018 16:40:21.568 +0500 ERROR MongodRunner - mongod exited abnormally (exit code 14, status: exited with code 14) - look at mongod.log to investigate.&lt;/P&gt;

&lt;P&gt;2018-09-20 11:53:28,490 ERROR   [5ba0dbbf9d126fbfbf240] root:130 - ENGINE: Handler for console events already off.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-Splunk-stop-collecting-syslog-logs/m-p/379774#M68603</guid>
      <dc:creator>lorder</dc:creator>
      <dc:date>2020-09-29T21:18:08Z</dc:date>
    </item>
  </channel>
</rss>

