<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitored input not showing on indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38811#M7172</link>
    <description>&lt;OL&gt;
&lt;LI&gt;How do you KNOW that you're not getting the DHCP logs indexed? &lt;/LI&gt;
&lt;LI&gt;What other data are you seeing from the forwarder?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Timestamps could be wrong. Have you searched for 'all time'?&lt;BR /&gt;
Try a metadata search, that should show if there are any data indexed on a per sourcetype basis. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| metadata type=sourcetypes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Permissions. &lt;BR /&gt;
You say you tried the rest interface (&lt;CODE&gt;https://[dhcphost]:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/CODE&gt;, I assume). Any errors listed? 100% done?&lt;/P&gt;

&lt;P&gt;Do you have permissions to access the index where the DHCP data is supposed to land? Is it searched by default, or would you have to specify &lt;CODE&gt;index=blaha&lt;/CODE&gt; as part of your search?&lt;/P&gt;

&lt;P&gt;/Kristian&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2012 20:19:22 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-04-27T20:19:22Z</dc:date>
    <item>
      <title>Monitored input not showing on indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38810#M7171</link>
      <description>&lt;P&gt;What am I missing here?  I have an indexer with the appropriate ports open and working, version 4.3.2.&lt;/P&gt;

&lt;P&gt;I install the UniversalForwarder onto a Windows DHCP server.  Stop the UniversalForwarder service, add the following config to $SPLUNKHOME\etc\system\local\input.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Windows\System32\dhcp]
sourcetype = DhcpSrvLog
crcSalt = &amp;lt;source&amp;gt;
alwaysOpenFile = 1
disabled = false
whitelist = Dhcp.+\.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart the service.  Check the inputstatus on the forwarder, (https://[dhcphost]:8089/services/admin/inputstatus/) and it has enumerated all the appropriate DHCP log files with correct sizes.&lt;/P&gt;

&lt;P&gt;Without doing anything else, I would expect the raw log entries to appear on the indexer.  I &lt;EM&gt;do&lt;/EM&gt; receive other system events from the same host on the indexer -- so I know the forwarder is working, but it isn't working for the monitored logs.  What am I missing?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 18:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38810#M7171</guid>
      <dc:creator>kingpin867</dc:creator>
      <dc:date>2012-04-27T18:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitored input not showing on indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38811#M7172</link>
      <description>&lt;OL&gt;
&lt;LI&gt;How do you KNOW that you're not getting the DHCP logs indexed? &lt;/LI&gt;
&lt;LI&gt;What other data are you seeing from the forwarder?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Timestamps could be wrong. Have you searched for 'all time'?&lt;BR /&gt;
Try a metadata search, that should show if there are any data indexed on a per sourcetype basis. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| metadata type=sourcetypes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Permissions. &lt;BR /&gt;
You say you tried the rest interface (&lt;CODE&gt;https://[dhcphost]:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/CODE&gt;, I assume). Any errors listed? 100% done?&lt;/P&gt;

&lt;P&gt;Do you have permissions to access the index where the DHCP data is supposed to land? Is it searched by default, or would you have to specify &lt;CODE&gt;index=blaha&lt;/CODE&gt; as part of your search?&lt;/P&gt;

&lt;P&gt;/Kristian&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 20:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38811#M7172</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-04-27T20:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitored input not showing on indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38812#M7173</link>
      <description>&lt;P&gt;Arggh, I'm embarrassed.  I wasn't using the correct terminology and everything was getting there correctly.  Thanks for the nudge!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 20:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38812#M7173</guid>
      <dc:creator>kingpin867</dc:creator>
      <dc:date>2012-04-27T20:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Monitored input not showing on indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38813#M7174</link>
      <description>&lt;P&gt;you're welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 20:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitored-input-not-showing-on-indexer/m-p/38813#M7174</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-04-27T20:56:16Z</dc:date>
    </item>
  </channel>
</rss>

