<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I get my first log message? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219259#M96151</link>
    <description>&lt;P&gt;Glad to hear you're receiving data. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2017 08:12:18 GMT</pubDate>
    <dc:creator>skalliger</dc:creator>
    <dc:date>2017-01-09T08:12:18Z</dc:date>
    <item>
      <title>How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219254#M96146</link>
      <description>&lt;P&gt;I have setup Universal forwarder on my Windows Server 2016 machine.&lt;/P&gt;

&lt;P&gt;I have setup the Universal forwarder credentials to point to my Splunk Cloud.&lt;/P&gt;

&lt;P&gt;By default shouldn't I now be getting data from the splunkd.log file?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 02:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219254#M96146</guid>
      <dc:creator>netroworx</dc:creator>
      <dc:date>2017-01-05T02:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219255#M96147</link>
      <description>&lt;P&gt;You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for &lt;STRONG&gt;index=_internal&lt;/STRONG&gt; and also specify &lt;STRONG&gt;host=xyz&lt;/STRONG&gt; if you'd like to.&lt;/P&gt;

&lt;P&gt;The other Spluk logs are also monitored, not only the splunkd.log.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 12:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219255#M96147</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-01-05T12:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219256#M96148</link>
      <description>&lt;P&gt;index=_internal shows a number of records.&lt;BR /&gt;
Some of the records show a host of WIN2016 which is the machine I'm monitoring but when I search on host=WIN2016 I get no results.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 23:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219256#M96148</guid>
      <dc:creator>netroworx</dc:creator>
      <dc:date>2017-01-05T23:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219257#M96149</link>
      <description>&lt;P&gt;Data Summary shows: "Waiting for results..."&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 23:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219257#M96149</guid>
      <dc:creator>netroworx</dc:creator>
      <dc:date>2017-01-05T23:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219258#M96150</link>
      <description>&lt;P&gt;If I search:&lt;BR /&gt;
index=_internal host=WIN2016&lt;/P&gt;

&lt;P&gt;I get results so I guess internal events are filtered out by default.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 00:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219258#M96150</guid>
      <dc:creator>netroworx</dc:creator>
      <dc:date>2017-01-06T00:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get my first log message?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219259#M96151</link>
      <description>&lt;P&gt;Glad to hear you're receiving data. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 08:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-my-first-log-message/m-p/219259#M96151</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-01-09T08:12:18Z</dc:date>
    </item>
  </channel>
</rss>

