<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarders stopped receiving some logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471932#M81097</link>
    <description>&lt;P&gt;Hi - yes, it's running. I don't see any .gz files in any directories.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 20:59:30 GMT</pubDate>
    <dc:creator>vnguyen46</dc:creator>
    <dc:date>2020-02-13T20:59:30Z</dc:date>
    <item>
      <title>Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471930#M81095</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a new HF once accepted logs for about a week, then stopped receiving on almost all logs at a same time.&lt;BR /&gt;
I compared this HF with the old working one and I don't see rotated logs created on the new HF.&lt;/P&gt;

&lt;P&gt;For instance, in log1 directory, I see log1.log  and several other copies like log1.log-date1.gz and log1.log-date2.gz and so on, but on the new HF I only see log1.log.&lt;/P&gt;

&lt;P&gt;I think not creating rotated logs on the HF could be the issue, but not sure and how to have these rotated logs created.&lt;BR /&gt;
Anyone can help, I appreciate it.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471930#M81095</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-02-13T20:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471931#M81096</link>
      <description>&lt;P&gt;Have you verified the new HF is running &lt;CODE&gt;(splunk status)&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471931#M81096</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-02-13T20:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471932#M81097</link>
      <description>&lt;P&gt;Hi - yes, it's running. I don't see any .gz files in any directories.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471932#M81097</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-02-13T20:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471933#M81098</link>
      <description>&lt;P&gt;Heavy Forwarders typically don't use a directory called "log1" so I wonder if you're looking at a syslog directory.  If so, make sure the syslog process is running and data sources are still sending to it (no new firewall rule is blocking them, for instance).&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 01:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471933#M81098</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-02-14T01:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471934#M81099</link>
      <description>&lt;P&gt;Hi richgalloway - on HF, log stored at: /opt/splunklogs/hostname/hostname.log&lt;BR /&gt;
I also see some files like hostname.log-timestamp.gz. Are these .gz files created by Splunk and supposed to be there?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 12:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471934#M81099</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-02-14T12:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders stopped receiving some logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471935#M81100</link>
      <description>&lt;P&gt;Usually those are created e.g. some syllogism variant not Splunk. You should figure out which tool is used on your environment to deliver / received those logs. Many times it is syslog, syslog-ng or rsyslog. And on network topology there could be a load balancer before those HF hosts to distribute events to all of those hosts.&lt;/P&gt;

&lt;P&gt;And probably there is also some log rotation tools to rotate and zip those logs?&lt;/P&gt;

&lt;P&gt;R. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 21:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarders-stopped-receiving-some-logs/m-p/471935#M81100</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-02-14T21:44:28Z</dc:date>
    </item>
  </channel>
</rss>

