<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Text logs not forwarded or indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515240#M87257</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an issue in forwarding application logs (text files) to splunk.&lt;BR /&gt;Windows Event Logs are forwarded and indexed properly but text files in a local drive are not.&lt;BR /&gt;Do you have any idea what the cause of this problem?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 14:51:49 GMT</pubDate>
    <dc:creator>MattMorish</dc:creator>
    <dc:date>2020-08-20T14:51:49Z</dc:date>
    <item>
      <title>Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515240#M87257</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an issue in forwarding application logs (text files) to splunk.&lt;BR /&gt;Windows Event Logs are forwarded and indexed properly but text files in a local drive are not.&lt;BR /&gt;Do you have any idea what the cause of this problem?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 14:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515240#M87257</guid>
      <dc:creator>MattMorish</dc:creator>
      <dc:date>2020-08-20T14:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515246#M87260</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;can you send your inputs.conf and outputs.conf files so community can help you?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 15:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515246#M87260</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-20T15:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515254#M87264</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Thank you for your quick reply. I'm attaching the conf.&lt;/P&gt;&lt;P&gt;--- inputs.conf ---&lt;/P&gt;&lt;P&gt;[monitor://\\vmappt123\CREMS-PLUS-IF\LOG\]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;BR /&gt;sourcetype =&lt;BR /&gt;whitelist = *.*&lt;/P&gt;&lt;P&gt;[monitor://\\vmappt123\CREMS-PLUS-IF\LOG]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;[monitor://\\vmappt123\CREMS-PLUS-IF\LOG\*.log*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;[monitor://D:\App\IVIF0001DJ\LOG]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;[monitor://D:\App\IVIF0001DJ\LOG\*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = default&lt;BR /&gt;sourcetype = MXG-CREMS Plus - Realtime&lt;/P&gt;&lt;P&gt;[monitor://\\vmappp123\CREMS-PLUS-IF\LOG\*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;BR /&gt;sourcetype = MXG-CREMS Plus - Realtime&lt;/P&gt;&lt;P&gt;[monitor://\\vmappt123\CREMS-PLUS-IF\LOG\*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;[monitor://\\vmappp123\CREMS-PLUS-IF\LOG]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;[monitor://D:\App\IVIF0001DJ\LOG\*.log*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;BR /&gt;sourcetype = MXG-CREMS Plus - Realtime&lt;/P&gt;&lt;P&gt;[monitor://\\vmappp123\CREMS-PLUS-IF\LOG\*.log*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;--- End of inputs.conf ---&lt;/P&gt;&lt;P&gt;--- outputs.conf ---&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = my_search_peers&lt;/P&gt;&lt;P&gt;[tcpout:my_search_peers]&lt;BR /&gt;server = v-spk01p:9997, v-spk01c:9997&lt;BR /&gt;autoLB = true&lt;/P&gt;&lt;P&gt;--- End of outputs.conf ---&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 15:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515254#M87264</guid>
      <dc:creator>MattMorish</dc:creator>
      <dc:date>2020-08-20T15:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515262#M87266</link>
      <description>&lt;P&gt;Anyone of those is working?&lt;/P&gt;&lt;P&gt;Are your splunk user in UF using local, domain or &amp;nbsp;service user? Based on your inputs it should be a domain or service.&lt;/P&gt;&lt;P&gt;Which version you are using?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 16:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515262#M87266</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-20T16:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515269#M87267</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;None of them is working, but according to TailingProcessor:FileStatus, it looks that the forwarder is successfully reading all files.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 640px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10409i0244436DFA39ADD5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;"Local System account" is selected on the tab "Log On" in the property of "SplunkForwarder Service" running&amp;nbsp;on the source server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are using Splunk Enterprise 6.6.6.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 17:32:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515269#M87267</guid>
      <dc:creator>MattMorish</dc:creator>
      <dc:date>2020-08-20T17:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515275#M87268</link>
      <description>&lt;P&gt;If I recall right, remote files should read with domain account not local? You could try to reset any of filepointer in fishbucket and see if it reread it. Otherwise I propose to use domain account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In whitelist those are regex so try .*\..* instead of *.*&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 18:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/515275#M87268</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-20T18:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Text logs not forwarded or indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/516033#M87355</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you very much for your helpful suggestion! We cracked the issue by doing as below.&lt;BR /&gt;1) Removed all the forwarded inputs that referenced network shares and just used local directories. Only 3 are present now (one of which must be working):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 600px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10497i30DFDC6DF924800E/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;2) Renamed one of the log files to have the extension .log&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 415px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10498i0969CE414638FE71/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;3) Adding a new line, the text has appeared in Splunk&lt;/P&gt;&lt;P&gt;We think its the third one we tried that's based on the regular expression that you suggested.&lt;BR /&gt;Thank you very much for pointing us the right direction!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 14:01:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Text-logs-not-forwarded-or-indexed/m-p/516033#M87355</guid>
      <dc:creator>MattMorish</dc:creator>
      <dc:date>2020-08-25T14:01:25Z</dc:date>
    </item>
  </channel>
</rss>

