<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing events from Splunk Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470085#M80839</link>
    <description>&lt;P&gt;Since this is a small file, can you use &lt;STRONG&gt;monitor&lt;/STRONG&gt; instead of &lt;STRONG&gt;batch&lt;/STRONG&gt; and check?&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 05:11:38 GMT</pubDate>
    <dc:creator>manjunathmeti</dc:creator>
    <dc:date>2020-02-11T05:11:38Z</dc:date>
    <item>
      <title>Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470082#M80836</link>
      <description>&lt;P&gt;I have one missing event out of 168 events from our Universal Forwarder. I've already checked the internal logs and the file has been indexed "Batch input finished reading file=", but I cannot find this source on my index. I also tried to expand time range and nothing appears, then check if the forwarder was restarted on the time of file was index, but it is not.  &lt;/P&gt;

&lt;P&gt;Settings on my forwarder is:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
[batch://my_path]&lt;BR /&gt;
move_policy = sinkhole&lt;BR /&gt;
disabled = false&lt;BR /&gt;
sourcetype = my_sourcetype&lt;BR /&gt;
index = my_index&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group-forwarder&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group-forwarder]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = myIndexer:9997&lt;BR /&gt;
useACK = true&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470082#M80836</guid>
      <dc:creator>iancorrea</dc:creator>
      <dc:date>2020-09-30T04:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470083#M80837</link>
      <description>&lt;P&gt;Is there any extraction or parsing done on sourcetype 'my_sourcetype'?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 04:50:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470083#M80837</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-11T04:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470084#M80838</link>
      <description>&lt;P&gt;yes, the other 167 events was successfully parsed&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 04:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470084#M80838</guid>
      <dc:creator>iancorrea</dc:creator>
      <dc:date>2020-02-11T04:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470085#M80839</link>
      <description>&lt;P&gt;Since this is a small file, can you use &lt;STRONG&gt;monitor&lt;/STRONG&gt; instead of &lt;STRONG&gt;batch&lt;/STRONG&gt; and check?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 05:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470085#M80839</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-11T05:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470086#M80840</link>
      <description>&lt;P&gt;I have been using batch since 1 month ago and there is no problem until this day. I cannot use the monitor because my client wants to use batch.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 08:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470086#M80840</guid>
      <dc:creator>iancorrea</dc:creator>
      <dc:date>2020-02-11T08:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Missing events from Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470087#M80841</link>
      <description>&lt;P&gt;Is this one event missing from a single log file?&lt;BR /&gt;
(ie the log contains 168 events, and only 167 have been indexed)&lt;BR /&gt;
Or is this one event from a batch of multiple files?&lt;/P&gt;

&lt;P&gt;The reason I ask is that it could be that the missing event did not break properly and was either merged, or dropped.&lt;/P&gt;

&lt;P&gt;If you still have the source log file, are you able to identify which event is missing, and does it appear "well formed" in the context of the other events?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 11:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-events-from-Splunk-Universal-Forwarder/m-p/470087#M80841</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-11T11:33:27Z</dc:date>
    </item>
  </channel>
</rss>

