<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs are stopped genarating from 2nd april in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553360#M91747</link>
    <description>&lt;P&gt;It's for only one user&amp;nbsp; it's happening . When I check for 2nd April these are logs genarating. In inputs they give correct path only and monitor the path is good&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20210527_212000.jpg" style="width: 2340px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14342i1BA9BCD0BB972B3A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20210527_212000.jpg" alt="Screenshot_20210527_212000.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; thanks in advance,&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 May 2021 15:53:39 GMT</pubDate>
    <dc:creator>anil1432</dc:creator>
    <dc:date>2021-05-27T15:53:39Z</dc:date>
    <item>
      <title>Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553134#M91723</link>
      <description>&lt;P&gt;My logs showing before April 2nd only when I check for previous 7 days it's not showing what may be the issue please share solution to us . But there is no error is showing . In actuall&amp;nbsp; the log is batchdog.log under this log there are similar logs are rolled like batchdog.lig.mmddyy.*log&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help please . There is no issues in splunkd.log also&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 12:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553134#M91723</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-26T12:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553146#M91725</link>
      <description>Hi&lt;BR /&gt;Are you sure that your date is parsed correctly in ingest phase? 2/4/2021 vs 4/2/2021?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Wed, 26 May 2021 13:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553146#M91725</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-26T13:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553220#M91730</link>
      <description>&lt;P&gt;Yes I checked all my data is parsing well.&lt;/P&gt;&lt;DIV&gt;My logs are stopped genarating from 3rd April and&amp;nbsp; when I check for 2nd April it's showing logs . And there is no issues available in&amp;nbsp; splunkd.log . And all my configuration are running fine . But only not genarating specific path&amp;nbsp; file only to a particular user . Plz hep me out&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 May 2021 02:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553220#M91730</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T02:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553222#M91731</link>
      <description>&lt;P&gt;My splunk enterprise version is 7.3.2&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 02:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553222#M91731</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T02:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553236#M91732</link>
      <description>&lt;P&gt;On UF side what it shows when you are writing as splunk/root (user which runs splunkd at UF):&lt;/P&gt;&lt;P&gt;splunk list inputstatus&lt;/P&gt;&lt;P&gt;You should find entry for that file like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;	/....../splunk/var/log/watchdog/watchdog.log
		file position = 5427
		file size = 5427
		parent = $SPLUNK_HOME/var/log/watchdog/watchdog.log*
		percent = 100.00
		type = finished reading&lt;/LI-CODE&gt;&lt;P&gt;This show if those files are read to end or are there something unread.&lt;/P&gt;&lt;P&gt;Are you getting any logs from that UF or only some?&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 06:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553236#M91732</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-27T06:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553256#M91735</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20210527_100943.jpg" style="width: 2340px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14328i706160F2D6A9CC4C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20210527_100943.jpg" alt="Screenshot_20210527_100943.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20210527_094844.jpg" style="width: 2340px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14329iDCA1303CA36DB6DA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20210527_094844.jpg" alt="Screenshot_20210527_094844.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; these are the errors I find outed sir&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 07:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553256#M91735</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T07:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553342#M91740</link>
      <description>&lt;P&gt;Can you post your inputs.conf and splunk list inputstatus?&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 15:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553342#M91740</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-27T15:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553356#M91746</link>
      <description>&lt;P&gt;I checked they are fine&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 15:43:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553356#M91746</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T15:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553360#M91747</link>
      <description>&lt;P&gt;It's for only one user&amp;nbsp; it's happening . When I check for 2nd April these are logs genarating. In inputs they give correct path only and monitor the path is good&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20210527_212000.jpg" style="width: 2340px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14342i1BA9BCD0BB972B3A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20210527_212000.jpg" alt="Screenshot_20210527_212000.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; thanks in advance,&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 15:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553360#M91747</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T15:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are stopped genarating from 2nd april</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553371#M91750</link>
      <description>&lt;P&gt;Let me try this? It will work or not?&lt;/P&gt;&lt;P&gt;/opt/splunk/var/log/watchdog/watchdog.log&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file position = 2518300&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file size = 2518300&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; parent = $SPLUNK_HOME/var/log/watchdog/watchdog.log*&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; percent = 100.00&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = open file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/var/log/watchdog/watchdog.log.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file position = 25000101&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file size = 25000101&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; parent = $SPLUNK_HOME/var/log/watchdog/watchdog.log*&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; percent = 100.00&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = finished reading&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 16:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-are-stopped-genarating-from-2nd-april/m-p/553371#M91750</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-05-27T16:34:54Z</dc:date>
    </item>
  </channel>
</rss>

