<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SPLUNK INDEX Discovery in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455271#M95267</link>
    <description>&lt;P&gt;Hi Guys, &lt;/P&gt;

&lt;P&gt;I have configured using index discovery for my forwarder which are forwarding my firewall logs.&lt;BR /&gt;
I saw from my splunkd.log it seems like the connection to my indexer is successful however, i can't see any logs from my indexer dashboard. &lt;/P&gt;

&lt;P&gt;x.x.x.x is my 1st index server&lt;BR /&gt;
y.y.y.y is my 2nd index server&lt;/P&gt;

&lt;H5&gt;logs&lt;/H5&gt;

&lt;P&gt;05-15-2019 03:59:05.238 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 03:59:10.784 +0800 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
05-15-2019 03:59:35.133 +0800 INFO  TcpOutputProc - Closing stream for idx=x.x.x.x:9997&lt;BR /&gt;
05-15-2019 03:59:35.133 +0800 INFO  TcpOutputProc - Connected to idx=y.y.y.y:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 03:59:40.785 +0800 INFO  TailReader -   ...continuing.&lt;BR /&gt;
05-15-2019 03:59:45.785 +0800 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
05-15-2019 04:00:08.725 +0800 INFO  TailReader -   ...continuing.&lt;BR /&gt;
05-15-2019 04:01:00.462 +0800 INFO  ArchiveProcessor - Handling file=/var/log/fortigate/fortigate.log-20190515.gz&lt;BR /&gt;
05-15-2019 04:01:00.462 +0800 INFO  ArchiveProcessor - new tailer already processed path=/var/log/fortigate/fortigate.log-20190515.gz&lt;BR /&gt;
05-15-2019 04:01:04.850 +0800 INFO  TcpOutputProc - Closing stream for idx=y.y.y.y:9997&lt;BR /&gt;
05-15-2019 04:01:04.850 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 04:03:04.453 +0800 INFO  TcpOutputProc - Closing stream for idx=x.x.x.x:9997&lt;BR /&gt;
05-15-2019 04:03:04.453 +0800 INFO  TcpOutputProc - Connected to idx=y.y.y.y::9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 04:04:04.270 +0800 INFO  TcpOutputProc - Closing stream for idx=y.y.y.y:9997&lt;BR /&gt;
05-15-2019 04:04:04.270 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;/P&gt;

&lt;P&gt;The indexes over at the index servers are not updated with any latest event as well. &lt;BR /&gt;
Any idea how i can troubleshoot on this issue ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 20:08:01 GMT</pubDate>
    <dc:creator>christay</dc:creator>
    <dc:date>2019-05-14T20:08:01Z</dc:date>
    <item>
      <title>SPLUNK INDEX Discovery</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455271#M95267</link>
      <description>&lt;P&gt;Hi Guys, &lt;/P&gt;

&lt;P&gt;I have configured using index discovery for my forwarder which are forwarding my firewall logs.&lt;BR /&gt;
I saw from my splunkd.log it seems like the connection to my indexer is successful however, i can't see any logs from my indexer dashboard. &lt;/P&gt;

&lt;P&gt;x.x.x.x is my 1st index server&lt;BR /&gt;
y.y.y.y is my 2nd index server&lt;/P&gt;

&lt;H5&gt;logs&lt;/H5&gt;

&lt;P&gt;05-15-2019 03:59:05.238 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 03:59:10.784 +0800 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
05-15-2019 03:59:35.133 +0800 INFO  TcpOutputProc - Closing stream for idx=x.x.x.x:9997&lt;BR /&gt;
05-15-2019 03:59:35.133 +0800 INFO  TcpOutputProc - Connected to idx=y.y.y.y:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 03:59:40.785 +0800 INFO  TailReader -   ...continuing.&lt;BR /&gt;
05-15-2019 03:59:45.785 +0800 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
05-15-2019 04:00:08.725 +0800 INFO  TailReader -   ...continuing.&lt;BR /&gt;
05-15-2019 04:01:00.462 +0800 INFO  ArchiveProcessor - Handling file=/var/log/fortigate/fortigate.log-20190515.gz&lt;BR /&gt;
05-15-2019 04:01:00.462 +0800 INFO  ArchiveProcessor - new tailer already processed path=/var/log/fortigate/fortigate.log-20190515.gz&lt;BR /&gt;
05-15-2019 04:01:04.850 +0800 INFO  TcpOutputProc - Closing stream for idx=y.y.y.y:9997&lt;BR /&gt;
05-15-2019 04:01:04.850 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 04:03:04.453 +0800 INFO  TcpOutputProc - Closing stream for idx=x.x.x.x:9997&lt;BR /&gt;
05-15-2019 04:03:04.453 +0800 INFO  TcpOutputProc - Connected to idx=y.y.y.y::9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;
05-15-2019 04:04:04.270 +0800 INFO  TcpOutputProc - Closing stream for idx=y.y.y.y:9997&lt;BR /&gt;
05-15-2019 04:04:04.270 +0800 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997, pset=0, reuse=0. using ACK.&lt;/P&gt;

&lt;P&gt;The indexes over at the index servers are not updated with any latest event as well. &lt;BR /&gt;
Any idea how i can troubleshoot on this issue ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 20:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455271#M95267</guid>
      <dc:creator>christay</dc:creator>
      <dc:date>2019-05-14T20:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK INDEX Discovery</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455272#M95268</link>
      <description>&lt;P&gt;Is your forwarder running as the splunk user? Files and directories under /var/log/ are typically owned by root. &lt;BR /&gt;
Try changing the user on your forwarder, or change the ownerships of your directory under /var/log/&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 22:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455272#M95268</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-05-14T22:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK INDEX Discovery</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455273#M95269</link>
      <description>&lt;P&gt;I have changed the ownership of /var/log to splunk user, but the result is still the same.&lt;BR /&gt;
The splunkd.log doesn't share much insight to the issue as well....&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 00:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-INDEX-Discovery/m-p/455273#M95269</guid>
      <dc:creator>christay</dc:creator>
      <dc:date>2019-05-15T00:54:21Z</dc:date>
    </item>
  </channel>
</rss>

