<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF is not sending few logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460477#M99464</link>
    <description>&lt;P&gt;Hi arunkns,&lt;BR /&gt;
at first check if you're receiving logs fron that server&lt;BR /&gt;
index=_internal host=your_server&lt;BR /&gt;
If yes, there's an ingestion problem, otherwise there's a connection problem.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:32:43 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-30T02:32:43Z</dc:date>
    <item>
      <title>UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460475#M99462</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have UF installed in my windows machine and its has IIS logs and App logs. In last few days, my forwarder is not sending App logs to indexers. I have other machine which is having same log files, but that is sending logs to indexer. So, i have compared the permissions of files and folder, but i'm not seeing any difference between both systems. Can you please suggest me how to fix it.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Arunkumar&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 07:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460475#M99462</guid>
      <dc:creator>arunkns</dc:creator>
      <dc:date>2019-10-15T07:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460476#M99463</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Have you checked &lt;CODE&gt;$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/CODE&gt; for any Warning or Error message on UF which is not sending data ? &lt;/P&gt;

&lt;P&gt;You can run &lt;CODE&gt;$SPLUNK_HOME\bin\splunk.exe list inputstatus&lt;/CODE&gt; on UF &amp;amp; you can check which file/directory UF is monitoring.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 07:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460476#M99463</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-10-15T07:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460477#M99464</link>
      <description>&lt;P&gt;Hi arunkns,&lt;BR /&gt;
at first check if you're receiving logs fron that server&lt;BR /&gt;
index=_internal host=your_server&lt;BR /&gt;
If yes, there's an ingestion problem, otherwise there's a connection problem.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460477#M99464</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460478#M99465</link>
      <description>&lt;P&gt;Thanks Harsmarvania57, I don't see any error in splunkd.log, but when I ran the command in windows (where UF is installed)  and got below error.&lt;/P&gt;

&lt;P&gt;AES-GCM Decryption failed!&lt;BR /&gt;
Decryption operation failed: AES-GCM Decryption failed!&lt;BR /&gt;
error:00000000:lib(0):func(0):reason(0)&lt;BR /&gt;
AES-GCM Decryption failed!&lt;BR /&gt;
Decryption operation failed: AES-GCM Decryption failed!&lt;BR /&gt;
error:00000000:lib(0):func(0):reason(0)&lt;BR /&gt;
AES-GCM Decryption failed!&lt;BR /&gt;
Decryption operation failed: AES-GCM Decryption failed!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 09:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460478#M99465</guid>
      <dc:creator>arunkns</dc:creator>
      <dc:date>2019-10-15T09:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460479#M99466</link>
      <description>&lt;P&gt;i'm able to see the host in _internal and the server has multiple logs like IIS and Apps. IIS logs are working fine, only apps logs are not coming into splunk&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 09:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460479#M99466</guid>
      <dc:creator>arunkns</dc:creator>
      <dc:date>2019-10-15T09:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: UF is not sending few logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460480#M99467</link>
      <description>&lt;P&gt;Hi arunkns,&lt;BR /&gt;
Could you share the input.conf stanza of app logs and a sample of your app logs?&lt;BR /&gt;
Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 09:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-is-not-sending-few-logs/m-p/460480#M99467</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-15T09:44:07Z</dc:date>
    </item>
  </channel>
</rss>

