<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not seeing any data ingesting to index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455684#M78800</link>
    <description>&lt;P&gt;I would recommend reading this: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Cantfinddata"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Did your source/client server received the app your created??Can you confirm if the files you're monitoring are readable by Splunk?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 15:29:17 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2019-08-16T15:29:17Z</dc:date>
    <item>
      <title>Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455683#M78799</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have created an app and add inputs.conf with the log path and the index name. &lt;BR /&gt;
Created a serverclass and added that app and the servers which need to ingest the data but I still cannot see any data ingesting to that index. &lt;/P&gt;

&lt;P&gt;Outputs.conf is already there on those servers and they are ingesting some data to other indexes. &lt;BR /&gt;
I don't know what I did wrong here. Please give some suggestions.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455683#M78799</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-16T15:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455684#M78800</link>
      <description>&lt;P&gt;I would recommend reading this: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Cantfinddata"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Did your source/client server received the app your created??Can you confirm if the files you're monitoring are readable by Splunk?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455684#M78800</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-16T15:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455685#M78801</link>
      <description>&lt;P&gt;Hi, Thanks for the reply. I asked that team to look if the app is deployed. Can you please let me know how to confirm if the files are readable by splunk.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455685#M78801</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-16T15:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455686#M78802</link>
      <description>&lt;P&gt;Have you checked the _internal indexes for the startup logs from the UF?&lt;/P&gt;

&lt;P&gt;It should show the UF reading in the Stanza's, do you see the input stanza in the logs?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;08-04-2019 11:37:07.050 -0500 INFO  WatchedFile - Will begin reading at offset=123 for file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\conf.log'.

08-04-2019 11:37:02.409 -0500 INFO  TailingProcessor - Adding watch on path: C:\Program Files\SplunkUniversalForwarder\var\log\splunk
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Do you see any error logs, related to access reading from the file location?&lt;/P&gt;

&lt;P&gt;Check the metrics logs?&lt;/P&gt;

&lt;P&gt;index=_* component=metrics group=per_source_thruput series=$file_location$&lt;/P&gt;

&lt;P&gt;Do you see this source getting forwarded?&lt;/P&gt;

&lt;P&gt;Check permissions on the file location and file, make sure the Splunk process can access it. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455686#M78802</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2020-09-30T01:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455687#M78803</link>
      <description>&lt;P&gt;When i checked this query which you mentioned above index=_* component=metrics group=per_source_thruput series=$file_location$, i did not find the path i just added to get the ingestion. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455687#M78803</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2020-09-30T01:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455688#M78804</link>
      <description>&lt;P&gt;Is the logs coming from a linux machine? If yes then you need to contact server admin to sudo login as account with which the Splunkd service is running and see if the file is readable (you can open in VIM editor OR run a tail command on the file with splunkd account).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 16:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455688#M78804</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-16T16:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455689#M78805</link>
      <description>&lt;P&gt;i will update to the person if you he can check these things to confirm if the splunk can read the file. &lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 16:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455689#M78805</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-16T16:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455690#M78806</link>
      <description>&lt;P&gt;can you let know how to check the permission of the file if it is in windows.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 18:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455690#M78806</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-16T18:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455691#M78807</link>
      <description>&lt;P&gt;You need to be much more specific with details.  What file are in what directories on what servers and what is in the files?  What are the permissions on those files?  What does &lt;CODE&gt;btool&lt;/CODE&gt; say?  What are the servers that touch the data on the way in?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2019 14:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455691#M78807</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-17T14:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455692#M78808</link>
      <description>&lt;P&gt;Did you check if the index is created and then if there is a problem in conf file props.conf &lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 18:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455692#M78808</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2019-08-18T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455693#M78809</link>
      <description>&lt;P&gt;Did you see any WatchedFile or TailingProcessor  events for the path?&lt;/P&gt;

&lt;P&gt;To be clear, you replaced $file_location$ with a regular expression that would match the path?&lt;/P&gt;

&lt;P&gt;If so, here's some steps:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Make sure you're receiving events to the internal index ( index=_* )&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Make sure you're getting metrics (index=_* component=Metrics)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Make sure you're getting events from the host in question ( index=_* host=$hostname$ )&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 19 Aug 2019 13:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455693#M78809</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2019-08-19T13:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Not seeing any data ingesting to index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455694#M78810</link>
      <description>&lt;P&gt;yes, I am getting the metric log. Today i got the information from the Application owner is that there is no data in those servers in the log path they provided me as they are brand new servers. I think everything should be good once there are some logs in that path. Thanks for the reply.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 13:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-seeing-any-data-ingesting-to-index/m-p/455694#M78810</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-19T13:54:25Z</dc:date>
    </item>
  </channel>
</rss>

