<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Free Edition stopped indexing after set-up in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Free-Edition-stopped-indexing-after-set-up/m-p/425172#M74538</link>
    <description>&lt;P&gt;I've tried browsing around previous topics but couldn't find anything that worked for my particular situation. I have a very simple test setup with a Universal Forwarder, a Debian 9 machine running the free edition of Splunk Enterprise, and another non-Splunk box. My goal was to simulate log forwarding from the workstation running the Universal Forwarder to the Splunk box to my non-Splunk box. I was indexing things up to 3 hours ago while troubleshooting why logs weren't being forwarded to my non-Splunk server. Eventually, I was able to get this data forwarded successfully to my non-Splunk server but then I noticed it stopped indexing on the Splunk server. No errors.&lt;/P&gt;

&lt;P&gt;My Splunk servers outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 10.X.1.99:514&lt;BR /&gt;
sendCookedData = false&lt;BR /&gt;
indexAndForward=true&lt;BR /&gt;
[tcpout-server://10.X.1.99:514]&lt;/P&gt;

&lt;P&gt;My Splunk servers inputs.conf; listening on 9997:&lt;BR /&gt;
[default]&lt;BR /&gt;
host = splunk&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;My Universal Forwarders outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 10.X.1.181:9997&lt;BR /&gt;
autoLB = true&lt;/P&gt;

&lt;P&gt;My Universal Forwarders inputs.conf (SOC workstation):&lt;BR /&gt;
[default]&lt;BR /&gt;
host = SOC-6&lt;/P&gt;

&lt;P&gt;Monitored Files:&lt;BR /&gt;
    $SPLUNK_HOME/etc/splunk.version&lt;BR /&gt;
    /var/log/auth.log&lt;BR /&gt;
    /var/log/syslog&lt;/P&gt;

&lt;P&gt;It's supposed to be a very basic setup. Like I said, I'm receiving logs on the non-Splunk box which was the main goal but I can't leave it partial with the Indexer not indexing. If you require further information feel free to request it. Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 23 Aug 2018 20:05:44 GMT</pubDate>
    <dc:creator>sploited</dc:creator>
    <dc:date>2018-08-23T20:05:44Z</dc:date>
    <item>
      <title>Splunk Free Edition stopped indexing after set-up</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Free-Edition-stopped-indexing-after-set-up/m-p/425172#M74538</link>
      <description>&lt;P&gt;I've tried browsing around previous topics but couldn't find anything that worked for my particular situation. I have a very simple test setup with a Universal Forwarder, a Debian 9 machine running the free edition of Splunk Enterprise, and another non-Splunk box. My goal was to simulate log forwarding from the workstation running the Universal Forwarder to the Splunk box to my non-Splunk box. I was indexing things up to 3 hours ago while troubleshooting why logs weren't being forwarded to my non-Splunk server. Eventually, I was able to get this data forwarded successfully to my non-Splunk server but then I noticed it stopped indexing on the Splunk server. No errors.&lt;/P&gt;

&lt;P&gt;My Splunk servers outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 10.X.1.99:514&lt;BR /&gt;
sendCookedData = false&lt;BR /&gt;
indexAndForward=true&lt;BR /&gt;
[tcpout-server://10.X.1.99:514]&lt;/P&gt;

&lt;P&gt;My Splunk servers inputs.conf; listening on 9997:&lt;BR /&gt;
[default]&lt;BR /&gt;
host = splunk&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;My Universal Forwarders outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 10.X.1.181:9997&lt;BR /&gt;
autoLB = true&lt;/P&gt;

&lt;P&gt;My Universal Forwarders inputs.conf (SOC workstation):&lt;BR /&gt;
[default]&lt;BR /&gt;
host = SOC-6&lt;/P&gt;

&lt;P&gt;Monitored Files:&lt;BR /&gt;
    $SPLUNK_HOME/etc/splunk.version&lt;BR /&gt;
    /var/log/auth.log&lt;BR /&gt;
    /var/log/syslog&lt;/P&gt;

&lt;P&gt;It's supposed to be a very basic setup. Like I said, I'm receiving logs on the non-Splunk box which was the main goal but I can't leave it partial with the Indexer not indexing. If you require further information feel free to request it. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 20:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Free-Edition-stopped-indexing-after-set-up/m-p/425172#M74538</guid>
      <dc:creator>sploited</dc:creator>
      <dc:date>2018-08-23T20:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Free Edition stopped indexing after set-up</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Free-Edition-stopped-indexing-after-set-up/m-p/425173#M74539</link>
      <description>&lt;P&gt;Did you check the free disk space on the indexer? The default value is 5000 Mb , see the docs &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf&lt;/A&gt; if the the free disk space is lower Splunk stops indexing.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 20:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Free-Edition-stopped-indexing-after-set-up/m-p/425173#M74539</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-08-23T20:55:23Z</dc:date>
    </item>
  </channel>
</rss>

