<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Old log files are not getting ingested into Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478403#M99792</link>
    <description>&lt;P&gt;At least, you should check the message in the splunkd.log. What can you find?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 13:59:20 GMT</pubDate>
    <dc:creator>tkomatsubara_sp</dc:creator>
    <dc:date>2019-09-09T13:59:20Z</dc:date>
    <item>
      <title>Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478401#M99790</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We got an requirement to ingest the xyz.log from a client machine.&lt;/P&gt;

&lt;P&gt;So i have created an app in the deployment master and deployed the same. The app has been successfully reached the client machine as well.&lt;/P&gt;

&lt;P&gt;I have created an app and deployed the same on 8th Sep 2019 and the log file (xyz.log) has been lastly updated on 5th Sep 2019 in the client machine. Actually i believe the log file should be ingested into Splunk Cloud but here in this case its not getting ingested into Splunk Cloud.&lt;/P&gt;

&lt;P&gt;So can i know what is the reason behind it and have enclosed my inputs.conf for reference. So kindly check and help on this.&lt;/P&gt;

&lt;P&gt;[monitor:///abc/def/ijk/lmn/xyz.log]&lt;BR /&gt;
sourcetype = pgr:stv&lt;BR /&gt;
index = 123&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;Kindly note the file has the splunk read permission and also in the internal logs it states that the configuration stanza as been parsed. The internal logs are reaching Splunk Cloud without any issues there is no connectivity issues as well.&lt;/P&gt;

&lt;P&gt;But still i couldn't able to see the logs in Splunk Cloud.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 13:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478401#M99790</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-09T13:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478402#M99791</link>
      <description>&lt;P&gt;Kindly help on my request&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 13:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478402#M99791</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-09T13:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478403#M99792</link>
      <description>&lt;P&gt;At least, you should check the message in the splunkd.log. What can you find?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 13:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478403#M99792</guid>
      <dc:creator>tkomatsubara_sp</dc:creator>
      <dc:date>2019-09-09T13:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478404#M99793</link>
      <description>&lt;P&gt;@tkomatsubara,&lt;/P&gt;

&lt;P&gt;In splunkd.log the file is getting parsed refer below:&lt;/P&gt;

&lt;P&gt;09-09-2019 05:20:30.415 -0500 INFO  TailingProcessor - Parsing configuration stanza: monitor:///abc/def/ijk/lmn/xyz.log&lt;/P&gt;

&lt;P&gt;But still the logs are not getting indexed. So can i know how Splunk works? Will it ingest old data as well.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 14:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478404#M99793</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-09T14:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478405#M99794</link>
      <description>&lt;P&gt;should i need to modify the inputs.conf stanza to ingest the old date logs. And the log date is on 5th Sep only. All seems to be fine but something it happens at the background and hence we couldn't able to ingest those logs.&lt;/P&gt;

&lt;P&gt;Is this how Splunk works? Is it wont be able to ingest the old data logs kindly confirm please.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 14:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478405#M99794</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-09T14:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478406#M99795</link>
      <description>&lt;P&gt;There must be some errors. Can you find?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 14:24:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478406#M99795</guid>
      <dc:creator>tkomatsubara_sp</dc:creator>
      <dc:date>2019-09-09T14:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478407#M99796</link>
      <description>&lt;P&gt;There are no errors at all. Am i missing anything in the stanza. And one thing can you confirm is splunk can index the old date data as well.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 07:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478407#M99796</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-10T07:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Old log files are not getting ingested into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478408#M99797</link>
      <description>&lt;P&gt;can anyone kindly help on my query.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 15:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-files-are-not-getting-ingested-into-Splunk-Cloud/m-p/478408#M99797</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-09-10T15:13:49Z</dc:date>
    </item>
  </channel>
</rss>

