<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I unable to read logfiles? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443391#M77213</link>
    <description>&lt;P&gt;I am trying to read log files from a server. I have made all the configuration in Splunk but data is not coming in Splunk search. When I checked Splunk's internal log, I got a permission denied error for that server. I logged to the specific server and verified that all users have read permission to path I am trying to Monitor. &lt;/P&gt;

&lt;P&gt;Can anyone suggest what could be the real cause for this issue.&lt;/P&gt;

&lt;P&gt;Below is the inputs.conf configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///usr2/oracle/saltlog/*logs.log]
sourcetype = oracle_os:healthcheck
index = os_na
interval = 600
crcSalt = &amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Below is the props.conf configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sourcetype:oracle_os:healthcheck]
SHOULD_LINEMERGE= true
NO_BINARY_CHECK = true
BREAK_ONLY_AFTER = TIMESTAMP=
TRUNCATE =9999
TZ = US/Eastern
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 05 Sep 2018 10:36:28 GMT</pubDate>
    <dc:creator>twh1</dc:creator>
    <dc:date>2018-09-05T10:36:28Z</dc:date>
    <item>
      <title>Why am I unable to read logfiles?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443391#M77213</link>
      <description>&lt;P&gt;I am trying to read log files from a server. I have made all the configuration in Splunk but data is not coming in Splunk search. When I checked Splunk's internal log, I got a permission denied error for that server. I logged to the specific server and verified that all users have read permission to path I am trying to Monitor. &lt;/P&gt;

&lt;P&gt;Can anyone suggest what could be the real cause for this issue.&lt;/P&gt;

&lt;P&gt;Below is the inputs.conf configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///usr2/oracle/saltlog/*logs.log]
sourcetype = oracle_os:healthcheck
index = os_na
interval = 600
crcSalt = &amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Below is the props.conf configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sourcetype:oracle_os:healthcheck]
SHOULD_LINEMERGE= true
NO_BINARY_CHECK = true
BREAK_ONLY_AFTER = TIMESTAMP=
TRUNCATE =9999
TZ = US/Eastern
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 05 Sep 2018 10:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443391#M77213</guid>
      <dc:creator>twh1</dc:creator>
      <dc:date>2018-09-05T10:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to read logfiles?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443392#M77214</link>
      <description>&lt;P&gt;Hi @twh1,&lt;/P&gt;

&lt;P&gt;Login to the server on which logfile exists and try to read that log files using &lt;CODE&gt;cat&lt;/CODE&gt; command with same user as splunk service is running and check whether there is any file permission issue is there or not. &lt;/P&gt;

&lt;P&gt;Additionally props.conf which you have provided should be on Indexer OR Heavy Forwarder whichever comes first from Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 10:45:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443392#M77214</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-09-05T10:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to read logfiles?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443393#M77215</link>
      <description>&lt;P&gt;Thanks @harsmarvania57 . I moved props.conf on indexer but after that also I was getting same error. There was an issue with folder permission. Splunk user had read permission for file but not for the folder. So I was getting permission denied error.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 17:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-read-logfiles/m-p/443393#M77215</guid>
      <dc:creator>twh1</dc:creator>
      <dc:date>2018-09-06T17:28:47Z</dc:date>
    </item>
  </channel>
</rss>

