<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk not ingesting some log files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479473#M82270</link>
    <description>&lt;P&gt;So splunk is able to read these files and into directories, yet they are not populating on the splunk server. &lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2020 12:06:19 GMT</pubDate>
    <dc:creator>user789</dc:creator>
    <dc:date>2020-04-23T12:06:19Z</dc:date>
    <item>
      <title>Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479469#M82266</link>
      <description>&lt;P&gt;I have set splunk to ingest the /var/log directory.  On this particular host, I go to filter by "source", and only see 2 sources:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;/var/log/messages&lt;/LI&gt;
&lt;LI&gt;/var/log/maillog&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Why is it not seeing other files and folders?  For example, there is /var/log/audit/audit.log.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 16:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479469#M82266</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-04-22T16:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479470#M82267</link>
      <description>&lt;P&gt;Does the account running Splunk have read access to the missing files?  Often, files in /var/log are secured so only root can read them.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 17:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479470#M82267</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-22T17:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479471#M82268</link>
      <description>&lt;P&gt;Splunk is running as "sudo", so this should be fine, right? &lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 17:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479471#M82268</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-04-22T17:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479472#M82269</link>
      <description>&lt;P&gt;"fine" as in able to read the files, yes.  "fine" as in a good way to run Splunk, no.  Running Splunk (or any non-OS process) as root increases your attack surface.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 18:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479472#M82269</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-22T18:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479473#M82270</link>
      <description>&lt;P&gt;So splunk is able to read these files and into directories, yet they are not populating on the splunk server. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 12:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479473#M82270</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-04-23T12:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479474#M82271</link>
      <description>&lt;P&gt;Search index=_internal to verify the forwarder is sending data to the indexers.  Verify you are looking in the right index for the data.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479474#M82271</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-24T13:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not ingesting some log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479475#M82272</link>
      <description>&lt;P&gt;I ran the query for index=_internal, and I do not see any of my hosts showing up. &lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 20:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-ingesting-some-log-files/m-p/479475#M82272</guid>
      <dc:creator>user789</dc:creator>
      <dc:date>2020-05-14T20:07:44Z</dc:date>
    </item>
  </channel>
</rss>

