<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why some logs are missing from splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373566#M92853</link>
    <description>&lt;P&gt;Hi Martin,&lt;BR /&gt;
surely you need SSH access to splunk servers, aniway they'll contact you.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 15:34:43 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-06-28T15:34:43Z</dc:date>
    <item>
      <title>why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373560#M92847</link>
      <description>&lt;P&gt;zcat syslog.*.gz | grep clamav&lt;/P&gt;

&lt;P&gt;i compare a successful one with the one who missing log in splunk, &lt;BR /&gt;
both have clamav summary log in syslog&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUc3hoOHVoVW5pM2c/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUc3hoOHVoVW5pM2c/view?usp=sharing&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUZ2tYdzhydHNpVms/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUZ2tYdzhydHNpVms/view?usp=sharing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373560#M92847</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T15:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373561#M92848</link>
      <description>&lt;P&gt;Hi cyberportnoc,&lt;BR /&gt;
check using a larger time period, often the problem is in differences in timestamp.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:18:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373561#M92848</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-28T15:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373562#M92849</link>
      <description>&lt;P&gt;i had used 7 days, still no log&lt;BR /&gt;
these log generated every day&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:20:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373562#M92849</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T15:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373563#M92850</link>
      <description>&lt;P&gt;&lt;A href="https://drive.google.com/file/d/0Bxs_ao6uuBDUVVBJcTczdlcwNUk/view?usp=sharing"&gt;https://drive.google.com/file/d/0Bxs_ao6uuBDUVVBJcTczdlcwNUk/view?usp=sharing&lt;/A&gt;&lt;BR /&gt;
use 30 days, still no log&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373563#M92850</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T15:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373564#M92851</link>
      <description>&lt;P&gt;i am Martin and sent to &lt;A href="mailto:support@splunk.com"&gt;support@splunk.com&lt;/A&gt;, but i do not know ssh's password of splunk, &lt;BR /&gt;
i can only have admin right to access web, so far at night shift. is there any one needed webex to investigate this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373564#M92851</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T15:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373565#M92852</link>
      <description>&lt;P&gt;Hi cyberportnoc,&lt;BR /&gt;
Temporarly send your syslogs to a test index for a little period and search on this index, in this way you can be sure that you're receiving logs.&lt;BR /&gt;
If there aren't there's a different problem to debug.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373565#M92852</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-28T15:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373566#M92853</link>
      <description>&lt;P&gt;Hi Martin,&lt;BR /&gt;
surely you need SSH access to splunk servers, aniway they'll contact you.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373566#M92853</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-28T15:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373567#M92854</link>
      <description>&lt;P&gt;after troubleshooting , i found the reasons that no log in these hosts, &lt;/P&gt;

&lt;P&gt;some reasons that log file are locked by another process&lt;BR /&gt;
,and some are misconfiguration of rsyslog.conf &lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 16:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373567#M92854</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T16:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: why some logs are missing from splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373568#M92855</link>
      <description>&lt;P&gt;i found the reason in the recorded video case, &lt;BR /&gt;
because the host use the same host name as another host, icnetwork01&lt;BR /&gt;
so the file actually is icnetwork01 which exist in the list&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 17:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-some-logs-are-missing-from-splunk/m-p/373568#M92855</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-06-28T17:00:10Z</dc:date>
    </item>
  </channel>
</rss>

