<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk universal forwarder isnt sending ONE folder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496472#M84682</link>
    <description>&lt;P&gt;both have root access&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2020 17:45:48 GMT</pubDate>
    <dc:creator>rtalcik</dc:creator>
    <dc:date>2020-03-16T17:45:48Z</dc:date>
    <item>
      <title>Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496469#M84679</link>
      <description>&lt;P&gt;So I have a seperate folder that was prebuilt from splunk universal forwarder.  &lt;/P&gt;

&lt;P&gt;The folder path is :&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/apps/"MY folders HERE"&lt;/P&gt;

&lt;P&gt;one of the folders under /apps IS sending&lt;/P&gt;

&lt;P&gt;the other folder is not and all it has is a path of&lt;/P&gt;

&lt;P&gt;/apps/NOT SENDING FOLDER/local/input.conf&lt;/P&gt;

&lt;P&gt;inside inputs.conf I have&lt;/P&gt;

&lt;P&gt;[monitor:///var/log/router/&lt;EM&gt;.log]&lt;BR /&gt;
host_regex=router/(.&lt;/EM&gt;).log&lt;BR /&gt;
sourcetype=cisco&lt;BR /&gt;
index=net&lt;BR /&gt;
crcSalt=&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;this is not monitoring the folder and NO logs are going into splunk&lt;/P&gt;

&lt;P&gt;however in the correct folder that is sending i have&lt;BR /&gt;
[monitor:///var/log/security.log]&lt;BR /&gt;
sourcetype = seclog&lt;BR /&gt;
index = sec&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;I also have the following folders in the correct logs that i do not have in the no working log&lt;/P&gt;

&lt;P&gt;default  local  metadata  README.md  static&lt;/P&gt;

&lt;P&gt;was wondering if anyone can point me in the direction to help me figure out why one folder is sending but the other isnt.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496469#M84679</guid>
      <dc:creator>rtalcik</dc:creator>
      <dc:date>2020-03-16T17:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496470#M84680</link>
      <description>&lt;P&gt;I don't think it's something to do with apps. Configurations looks correct. Check user running splunk process has read permissions to log files in directory &lt;EM&gt;/var/log/router/&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;If user has read permissions then check for any errors in splunkd logs in  /opt/splunkforwarder/var/log/splunk/.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496470#M84680</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-16T17:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496471#M84681</link>
      <description>&lt;P&gt;very good point I will do.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496471#M84681</guid>
      <dc:creator>rtalcik</dc:creator>
      <dc:date>2020-03-16T17:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496472#M84682</link>
      <description>&lt;P&gt;both have root access&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496472#M84682</guid>
      <dc:creator>rtalcik</dc:creator>
      <dc:date>2020-03-16T17:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496473#M84683</link>
      <description>&lt;P&gt;permissions seem fine.  they all have root accesss rw both ways&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 18:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496473#M84683</guid>
      <dc:creator>rtalcik</dc:creator>
      <dc:date>2020-03-16T18:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496474#M84684</link>
      <description>&lt;P&gt;Is root running splunk process? Check splunkd logs /opt/splunkforwarder/var/log/splunk/splunkd.logs and also check if index "net" is created on indexer servers.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 18:19:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496474#M84684</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-16T18:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder isnt sending ONE folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496475#M84685</link>
      <description>&lt;P&gt;So i fixed this issue but investigating the errors in splunkd logs like manjuanthemeti said above.&lt;/P&gt;

&lt;P&gt;This was resolved by finding out what the issue was and removing empty log files in the directory.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 20:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-isnt-sending-ONE-folder/m-p/496475#M84685</guid>
      <dc:creator>rtalcik</dc:creator>
      <dc:date>2020-03-16T20:56:01Z</dc:date>
    </item>
  </channel>
</rss>

