<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk not receiving data from forwarder - tried everything in documentation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315371#M93512</link>
    <description>&lt;P&gt;Adding my /etc/system/local/outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = MY.INDEXER.IP:9999&lt;/P&gt;

&lt;P&gt;[tcpout-server://MY.INDEXER.IP:9999]&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2018 22:25:05 GMT</pubDate>
    <dc:creator>Leavittinc</dc:creator>
    <dc:date>2018-01-13T22:25:05Z</dc:date>
    <item>
      <title>Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315370#M93511</link>
      <description>&lt;P&gt;Let me preface by saying I've read through multiple threads and tried their recommendations with no luck.&lt;/P&gt;

&lt;P&gt;I have a splunk enterprise indexer that is not receiving data from a splunk universal forwarder on a remote server.&lt;BR /&gt;
When I set it up, it initially sent the data, but since has not updated with new information.&lt;/P&gt;

&lt;P&gt;I confirmed that my local box is recieving the connection. There are live established connections between the two over port 9999 (which I set). I confirmed that the firewall rules between here and there are perfectly fine. The connections are happening, but no data is flowing.&lt;/P&gt;

&lt;P&gt;I have a data input set up in the indexer and it's enabled. &lt;/P&gt;

&lt;P&gt;My inputs.conf in $SPLUNK/etc/apps/search/local :&lt;/P&gt;

&lt;P&gt;[monitor:///home/admin/web/MYSERVER/logs/MYSERVER.log]&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;My inputs.conf in $SPLUNK/etc/system/local:&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = MYSERVER.NET&lt;/P&gt;

&lt;P&gt;The tail end of my splunkd.log on the forwarder:&lt;/P&gt;

&lt;P&gt;01-13-2018 16:07:02.330 -0500 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk/...stash_new.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/etc/splunk.version.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/license_usage_summary.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/metrics.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/splunkd.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor:///home/admin/web/MYSERVER.net/logs/MYSERVER.net.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor://home/admin/web/MYSERVER.net/logs/MYSERVER.net.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 ERROR TailingProcessor - Input stanza path, 'home/admin/web/MYSERVER.net/logs/MYSERVER.net.log' is not absolute.  This is a configuration error and may not work / break things.  Change this path to an absolute path.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Adding watch on path: /home/admin/web/MYSERVER.net/logs/MYSERVER.net.log.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Adding watch on path: /home/admin/web/MYSERVER.net/splunkforwarder/etc/splunk.version.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Adding watch on path: /home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk.&lt;BR /&gt;
01-13-2018 16:07:02.332 -0500 INFO  TailingProcessor - Adding watch on path: /home/admin/web/MYSERVER.net/splunkforwarder/var/spool/splunk.&lt;BR /&gt;
01-13-2018 16:07:02.333 -0500 INFO  loader - Limiting REST HTTP server to 21845 sockets&lt;BR /&gt;
01-13-2018 16:07:02.333 -0500 INFO  loader - Limiting REST HTTP server to 170 threads&lt;BR /&gt;
01-13-2018 16:07:02.333 -0500 WARN  X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &lt;BR /&gt;
01-13-2018 16:07:02.343 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/mongod.log'.&lt;BR /&gt;
01-13-2018 16:07:02.345 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/splunkd_ui_access.log'.&lt;BR /&gt;
01-13-2018 16:07:02.346 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/license_usage_summary.log'.&lt;BR /&gt;
01-13-2018 16:07:02.350 -0500 INFO  WatchedFile - Will begin reading at offset=1556 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/splunkd_stderr.log'.&lt;BR /&gt;
01-13-2018 16:07:02.403 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/btool.log'.&lt;BR /&gt;
01-13-2018 16:07:02.431 -0500 INFO  WatchedFile - Will begin reading at offset=10800 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/splunkd-utility.log'.&lt;BR /&gt;
01-13-2018 16:07:02.437 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/searchhistory.log'.&lt;BR /&gt;
01-13-2018 16:07:02.440 -0500 INFO  WatchedFile - Will begin reading at offset=4740 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/conf.log'.&lt;BR /&gt;
01-13-2018 16:07:02.465 -0500 INFO  WatchedFile - Will begin reading at offset=3303363 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/metrics.log'.&lt;BR /&gt;
01-13-2018 16:07:02.468 -0500 INFO  WatchedFile - Will begin reading at offset=87350 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/audit.log'.&lt;BR /&gt;
01-13-2018 16:07:02.471 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/license_usage.log'.&lt;BR /&gt;
01-13-2018 16:07:02.474 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/remote_searches.log'.&lt;BR /&gt;
01-13-2018 16:07:02.476 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/scheduler.log'.&lt;BR /&gt;
01-13-2018 16:07:02.503 -0500 INFO  WatchedFile - Will begin reading at offset=2426 for file='/home/admin/web/MYSERVER.net/splunkforwarder/var/log/splunk/splunkd_stdout.log'.&lt;BR /&gt;
01-13-2018 16:07:02.515 -0500 INFO  TcpOutputProc - Connected to idx=MY.INDEXER.I.P:9999, pset=0, reuse=0.&lt;BR /&gt;
01-13-2018 16:07:14.118 -0500 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
01-13-2018 16:07:26.119 -0500 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
01-13-2018 16:07:33.715 -0500 INFO  ProxyConfig - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=&lt;A href="http://host:port" target="_blank"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;
01-13-2018 16:07:33.715 -0500 INFO  ProxyConfig - Failed to initialize https_proxy from server.conf for splunkd. Please make sure that the https_proxy property is set as https_proxy=&lt;A href="http://host:port" target="_blank"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;
01-13-2018 16:07:33.715 -0500 INFO  ProxyConfig - Failed to initialize the no_proxy setting from server.conf for splunkd. Please provide a valid set of no_proxy rules in case HTTP proxying needs to be enabled.&lt;BR /&gt;
01-13-2018 16:07:33.925 -0500 INFO  HttpPubSubConnection - SSL connection with id: connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:07:34.149 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:07:38.119 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:07:38.176 -0500 INFO  DC:HandshakeReplyHandler - Handshake done.&lt;BR /&gt;
01-13-2018 16:08:38.176 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:08:38.372 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:09:38.419 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:10:38.615 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:11:38.908 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;BR /&gt;
01-13-2018 16:12:39.109 -0500 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_MY.FORWARDER.I.P_8089_MY.FORWARDER.I.P_server_B47A56B6-7904-4954-98AE-8D56B372CFCF&lt;/P&gt;

&lt;P&gt;I'm a noob to splunk and am not sure what else to do, I've followed the steps in the documentation.&lt;/P&gt;

&lt;P&gt;Any ideas ?? Thanks ahead of time for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315370#M93511</guid>
      <dc:creator>Leavittinc</dc:creator>
      <dc:date>2020-09-29T17:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315371#M93512</link>
      <description>&lt;P&gt;Adding my /etc/system/local/outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = MY.INDEXER.IP:9999&lt;/P&gt;

&lt;P&gt;[tcpout-server://MY.INDEXER.IP:9999]&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 22:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315371#M93512</guid>
      <dc:creator>Leavittinc</dc:creator>
      <dc:date>2018-01-13T22:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315372#M93513</link>
      <description>&lt;P&gt;Hey looking at splunkd.log&lt;/P&gt;

&lt;P&gt;You got a &lt;CODE&gt;ERROR&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;01-13-2018 16:07:02.332 -0500 ERROR TailingProcessor - Input stanza path, 'home/admin/web/MYSERVER.net/logs/MYSERVER.net.log' is not absolute. This is a configuration error and may not work / break things. Change this path to an absolute path.&lt;/P&gt;

&lt;P&gt;So in your monitor stanza provide full path with the root directory.&lt;/P&gt;

&lt;P&gt;If you want to know what is absolute path?&lt;BR /&gt;
So here is the answer,an absolute path is defined as the specifying the location of a file or directory from the root directory(/). In other words we can say absolute path is a complete path from start of actual filesystem from / directory.&lt;/P&gt;

&lt;P&gt;Also enable receiving on the &lt;CODE&gt;indexer&lt;/CODE&gt; if you have not:&lt;/P&gt;

&lt;P&gt;To enable receiving,login on indexer:&lt;BR /&gt;
Go to &lt;CODE&gt;Settings » Forwarding and receiving » Receive data » Add new&lt;/CODE&gt; Put &lt;CODE&gt;9999&lt;/CODE&gt; and click save.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2018 15:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315372#M93513</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-14T15:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315373#M93514</link>
      <description>&lt;P&gt;Please refer to &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.1/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2018 15:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315373#M93514</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-14T15:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315374#M93515</link>
      <description>&lt;P&gt;Did you restart the Splunk service after making changes to your conf files?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2018 16:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315374#M93515</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-01-14T16:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not receiving data from forwarder - tried everything in documentation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315375#M93516</link>
      <description>&lt;P&gt;In addition to all of these, have you checked internal on your indexer to see if you can see the forwarders internal logs?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal | stats count by host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That will validate if the UF / Forwarder is connecting, and if the problem is in your inputs. Additionally try oneshot'ing a file from your forwarder and see if you can search it.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 04:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-receiving-data-from-forwarder-tried-everything-in/m-p/315375#M93516</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2018-01-15T04:10:57Z</dc:date>
    </item>
  </channel>
</rss>

