<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarder only sends Error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-only-sends-Error/m-p/48786#M9258</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm new to Splunk, only started evaluating it for a few days.&lt;/P&gt;

&lt;P&gt;I'm using the SplunkForwarder to monitor a log file on a windows machine: &lt;STRONG&gt;splunk.exe add monitor c:\path_to_the_log_file&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;My log file contains, INFO, WARN and ERROR messages.&lt;BR /&gt;
It looks something like:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;2012-11-29 03:00:11,515 [1] ERROR test_logs.Program [(null)] - Message 3&lt;/P&gt;

&lt;P&gt;2012-11-29 03:00:12,515 [1] WARN test_logs.Program [(null)] - Message 4&lt;/P&gt;

&lt;P&gt;2012-11-29 03:03:11,515 [1] INFO test_logs.Program [(null)] - Message 1&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;It's working as far as I can see (and search) the ERROR entries on the Splunk server. My problem is that I'm not seeing any of the INFO or WARN entries showing in the logs on the server.&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;BR /&gt;
Didier,&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:53:00 GMT</pubDate>
    <dc:creator>didier_again</dc:creator>
    <dc:date>2020-09-28T12:53:00Z</dc:date>
    <item>
      <title>Forwarder only sends Error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-only-sends-Error/m-p/48786#M9258</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm new to Splunk, only started evaluating it for a few days.&lt;/P&gt;

&lt;P&gt;I'm using the SplunkForwarder to monitor a log file on a windows machine: &lt;STRONG&gt;splunk.exe add monitor c:\path_to_the_log_file&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;My log file contains, INFO, WARN and ERROR messages.&lt;BR /&gt;
It looks something like:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;2012-11-29 03:00:11,515 [1] ERROR test_logs.Program [(null)] - Message 3&lt;/P&gt;

&lt;P&gt;2012-11-29 03:00:12,515 [1] WARN test_logs.Program [(null)] - Message 4&lt;/P&gt;

&lt;P&gt;2012-11-29 03:03:11,515 [1] INFO test_logs.Program [(null)] - Message 1&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;It's working as far as I can see (and search) the ERROR entries on the Splunk server. My problem is that I'm not seeing any of the INFO or WARN entries showing in the logs on the server.&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;BR /&gt;
Didier,&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:53:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-only-sends-Error/m-p/48786#M9258</guid>
      <dc:creator>didier_again</dc:creator>
      <dc:date>2020-09-28T12:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder only sends Error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-only-sends-Error/m-p/48787#M9259</link>
      <description>&lt;P&gt;Please Ignore this, the problem was not Splunk related.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-only-sends-Error/m-p/48787#M9259</guid>
      <dc:creator>didier_again</dc:creator>
      <dc:date>2012-11-29T16:56:25Z</dc:date>
    </item>
  </channel>
</rss>

