<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting splunk logs in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703781#M10535</link>
    <description>&lt;P&gt;That might indicate issues with the receiving indexer. Check its logs and health.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 09:12:36 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-11-07T09:12:36Z</dc:date>
    <item>
      <title>Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703703#M10531</link>
      <description>&lt;P&gt;After&amp;nbsp;&amp;nbsp;Splunk forwarder version got upgrade&amp;nbsp;from 9.0.5.0 to 9.3.1.0 windows server are having issue in forwarding the data to Splunk.&lt;BR /&gt;&lt;BR /&gt;Splunkd is stopping often in different server after restarting splund it start forwarding the data but issue comes again after 2,3 days&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;what actions to be taken to make the logs flow easily to Splunk&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 16:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703703#M10531</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2024-11-06T16:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703760#M10532</link>
      <description>&lt;P&gt;The biggest change on the Universal forwarder from 9.0. &amp;gt; 9.3 was&amp;nbsp;&lt;SPAN class=""&gt;least-privileged user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.3.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Manage_SePrivilegeUser_permissions" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Forwarder/9.3.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Manage_SePrivilegeUser_permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any issues on the permissions? I recommend working with support if this is happening frequently on all your windows hosts.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If this reply helps, Please UpVote.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 04:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703760#M10532</guid>
      <dc:creator>sainag_splunk</dc:creator>
      <dc:date>2024-11-07T04:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703774#M10533</link>
      <description>&lt;P&gt;Firstly, check what happens - when the UF "stops", check what's at the end of splunkd.log to see whether anything out of the ordinary happened and see the windows system/application logs for entries regarding splunkd.exe to see if you see any indication of process crashing.&lt;/P&gt;&lt;P&gt;It might be a configuration issue but it indeed might be a software bug so you might end up calling support for help.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 08:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703774#M10533</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-07T08:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703780#M10534</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;error is something like&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class=""&gt;Read error. An existing connection was forcibly closed by the remote host.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 09:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703780#M10534</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2024-11-07T09:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703781#M10535</link>
      <description>&lt;P&gt;That might indicate issues with the receiving indexer. Check its logs and health.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 09:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703781#M10535</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-07T09:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703785#M10537</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;like while am searching in Splunk indexer am not able to see host, index and source for the windows server at that specific time.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 09:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703785#M10537</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2024-11-07T09:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703790#M10539</link>
      <description>&lt;P&gt;No. I don't mean searching for the logs from the forwarder. This you won't find, it's obvious.&lt;/P&gt;&lt;P&gt;You need to look into _internal log for events from your receiving indexer(s) or HF(s) depending on what your infrastructure looks like concerning that disconnecting forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 10:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703790#M10539</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-07T10:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703904#M10544</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so basically there is window server they had U.F which is forwarding data to Splunk.&lt;BR /&gt;&lt;BR /&gt;While I checked the _internal logs not able to find anything on search head . What should I do next&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 09:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703904#M10544</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2024-11-08T09:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting splunk logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703939#M10545</link>
      <description>&lt;P&gt;There is no obvious answer. It might indeed require calling support.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 15:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-getting-splunk-logs/m-p/703939#M10545</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-08T15:47:49Z</dc:date>
    </item>
  </channel>
</rss>

