<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Insights for Infrastructure - Data Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443572#M77243</link>
    <description>&lt;P&gt;Hi, does anyone have any suggestions?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jun 2018 17:52:59 GMT</pubDate>
    <dc:creator>ric878</dc:creator>
    <dc:date>2018-06-12T17:52:59Z</dc:date>
    <item>
      <title>Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443571#M77242</link>
      <description>&lt;P&gt;Hi, I recently installed Splunk Insights for Infrastructure on a virtual machine. After going through the setup process I proceeded to setup my first entity. I copied and pasted the generated script, modified it to ignore certificate errors and after a couple of minutes it was available in Splunk. Problem is that I'm only getting metrics data from collectd, but I do not see any log information.&lt;/P&gt;

&lt;P&gt;I followed the troubleshooting information found here &lt;A href="http://docs.splunk.com/Documentation/Infrastructure/1.0.1/Admin/Troubleshooting"&gt;http://docs.splunk.com/Documentation/Infrastructure/1.0.1/Admin/Troubleshooting&lt;/A&gt; but was not able to resolve my issue. I can confirm that the Splunk forwarder is online, and that port 9997 is not blocked. On the SII machine, I see a repeated error in the splunk.log file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:47.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
06-11-2018 01:34:58.616 -0500 ERROR LMStack - Invalid License with infinite byte quota with non-infinite max_stack_quota byte, set the effective stack size to the min between them
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm not sure if that is related at all. Any help would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ricardo&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 14:35:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443571#M77242</guid>
      <dc:creator>ric878</dc:creator>
      <dc:date>2018-06-11T14:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443572#M77243</link>
      <description>&lt;P&gt;Hi, does anyone have any suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 17:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443572#M77243</guid>
      <dc:creator>ric878</dc:creator>
      <dc:date>2018-06-12T17:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443573#M77244</link>
      <description>&lt;P&gt;Was this installed on an instance with an existing splunk install?&lt;/P&gt;

&lt;P&gt;Did you install any other licenses than the default license that came with the Splunk Insights for Infrastructure package?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 02:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443573#M77244</guid>
      <dc:creator>ntankersley_spl</dc:creator>
      <dc:date>2018-06-18T02:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443574#M77245</link>
      <description>&lt;P&gt;Clean install on a new virtual machine. No other previous Splunk software. Should I just destroy the VM and try again?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 02:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443574#M77245</guid>
      <dc:creator>ric878</dc:creator>
      <dc:date>2018-06-18T02:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443575#M77246</link>
      <description>&lt;P&gt;I don't think the errors for the license are associated. Let's check for log files on the instance. In the command line go to $SPLUNK_HOME/splunk/bin and run&lt;/P&gt;

&lt;P&gt;./splunk search "index=main | stats count by host" and see what comes out. You should see the same host with a count of logs collected. If nothing returns then you aren't getting any data in and we'll have to try something different.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443575#M77246</guid>
      <dc:creator>ntankersley_spl</dc:creator>
      <dc:date>2018-06-19T16:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443576#M77247</link>
      <description>&lt;P&gt;Okay, I ran the command and I do not see any hosts and log counts. It would seem that I am not getting any logs into the SII instance.&lt;/P&gt;

&lt;P&gt;Also, just to be 100% sure, I deleted the VM and started over, re-added the machine I wanted to monitor and came up with the same results, I'm getting metrics but no logs. I also ran the command again and again did not see any hosts and log counts.&lt;/P&gt;

&lt;P&gt;I've double check the firewall on the SII instance and confirmed that I have the following ports open:&lt;BR /&gt;
8000&lt;BR /&gt;
8088&lt;BR /&gt;
8089&lt;BR /&gt;
9997&lt;/P&gt;

&lt;P&gt;Any other suggestions?&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 22:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443576#M77247</guid>
      <dc:creator>ric878</dc:creator>
      <dc:date>2018-06-20T22:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443577#M77248</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;After my attempted reinstall, I went back and ran the command again to double check and to my surprise, I see two hosts with index data. I still do not see logs in the interface but it would seem the SII instance is getting the log data. Maybe I tried to soon after adding a host. So, one step closer but still no log data visible in the web GUI.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 04:44:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443577#M77248</guid>
      <dc:creator>ric878</dc:creator>
      <dc:date>2018-07-01T04:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Insights for Infrastructure - Data Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443578#M77249</link>
      <description>&lt;P&gt;Same problem - I can see logs in console but not in the interface&lt;BR /&gt;
host   count&lt;BR /&gt;
srv-ad-1 55235&lt;BR /&gt;
[root@srv-splunk bin]#,Same problem - I can see logs in console but not on the interface&lt;/P&gt;

&lt;P&gt;host   count&lt;BR /&gt;
srv-ad-1 55235&lt;BR /&gt;
[root@srv-splunk bin]#&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 11:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Insights-for-Infrastructure-Data-Logs/m-p/443578#M77249</guid>
      <dc:creator>degreeds</dc:creator>
      <dc:date>2018-09-21T11:03:45Z</dc:date>
    </item>
  </channel>
</rss>

