<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Receiving Logs from Syslog Server in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536113#M4731</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230563"&gt;@kpcool&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;so, you have a ng-syslogs server that writes syslogs in files that are read by a UF and you deploy configrations (TAs) to the UF using a Deployment Server.&lt;/P&gt;&lt;P&gt;I don't know particular limitations to files to read by UF, are you sure that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the TA containing your inputs.conf is correctly deployed to the UF (check this in $SPLUNK/etc/apps)?&lt;/LI&gt;&lt;LI&gt;that Splunk is restarted on UF after upgrade?&lt;/LI&gt;&lt;LI&gt;that the path in the inputs.conf is correct?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you share the path of the folder containing the files to read and the inputs.conf?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sat, 16 Jan 2021 12:29:58 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-01-16T12:29:58Z</dc:date>
    <item>
      <title>Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536109#M4728</link>
      <description>&lt;P&gt;I have set up universal forwarder to collect the all syslog data to splunk. All the settings are in place&lt;/P&gt;&lt;P&gt;1. Connectivity between the servers (syslog UF to Splunk) is ok&lt;/P&gt;&lt;P&gt;2. Required ports are open&lt;/P&gt;&lt;P&gt;3. All the configuration on syslog server and deployment server is ok.&lt;/P&gt;&lt;P&gt;4. Even after making the changes in inputs under deployment server app, i used to restart the app by GUI.&lt;/P&gt;&lt;P&gt;5. On syslog i getting continuous logs.&lt;/P&gt;&lt;P&gt;However all the settings are in place, im not able to receive the continuous logs. Sometimes i receive the logs to splunk. but sometimes the logs are not getting received.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 10:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536109#M4728</guid>
      <dc:creator>kpcool</dc:creator>
      <dc:date>2021-01-16T10:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536111#M4729</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230563"&gt;@kpcool&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you configured an ng-syslog server that writes logs in files and UF reads files,&lt;/LI&gt;&lt;LI&gt;or did you configured your UF to directly take syslogs?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In the first case, check if the files containing syslogs are present and then check if the input.conf stanza reads the correct path.&lt;/P&gt;&lt;P&gt;In the second case, I knew that you cannot use an Universal Forwarder to take syslogs but you need an Heavy Forwarder to do this, infact you can find infos at &lt;A href="https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input" target="_blank"&gt;https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input&lt;/A&gt;&amp;nbsp;, searching for this question I found that also Uf can be used to input syslogs, but I never used it, always HF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 10:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536111#M4729</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-16T10:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536112#M4730</link>
      <description>&lt;P&gt;I'm collecting the network logs to syslog server, where I have installed the UF. Through UF I'm monitoring those log files. I have deployment server as well.&lt;BR /&gt;input.conf is correct, as sometimes logs are coming sometimes not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any restriction of UF that it cant read large size files?&lt;/P&gt;&lt;P&gt;we are not using HF in our environment.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 12:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536112#M4730</guid>
      <dc:creator>kpcool</dc:creator>
      <dc:date>2021-01-16T12:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536113#M4731</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230563"&gt;@kpcool&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;so, you have a ng-syslogs server that writes syslogs in files that are read by a UF and you deploy configrations (TAs) to the UF using a Deployment Server.&lt;/P&gt;&lt;P&gt;I don't know particular limitations to files to read by UF, are you sure that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the TA containing your inputs.conf is correctly deployed to the UF (check this in $SPLUNK/etc/apps)?&lt;/LI&gt;&lt;LI&gt;that Splunk is restarted on UF after upgrade?&lt;/LI&gt;&lt;LI&gt;that the path in the inputs.conf is correct?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you share the path of the folder containing the files to read and the inputs.conf?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 12:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536113#M4731</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-16T12:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536163#M4732</link>
      <description>Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;, The points you mentioned are all correct. Also im getting the logs sometimes and sometimes its not. Here is the input from deployment server, [monitor:///data/syslog/xyz/] index = pqr host_segment = 3 disabled = 0 sourcetype = abc Note: For data privacy, i have used the alphabetical words, file path us under monitor segment in inputs</description>
      <pubDate>Mon, 18 Jan 2021 06:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536163#M4732</guid>
      <dc:creator>kpcool</dc:creator>
      <dc:date>2021-01-18T06:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving Logs from Syslog Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536166#M4733</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230563"&gt;@kpcool&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if sometimes you take logs and sometimes not, you have a correct input configuration.&lt;/P&gt;&lt;P&gt;Now we have to check why, sometimes not!&lt;/P&gt;&lt;P&gt;Please check if the times that you don't index files, the content of the file is the same of the previous one (also with a different filename), because Splunk by default doesn't index twice a log also if in different files.&lt;/P&gt;&lt;P&gt;If this is your situation, you have to add to your inputs.conf stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;In this way splunk index all the files with different filename.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 07:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Not-Receiving-Logs-from-Syslog-Server/m-p/536166#M4733</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-18T07:23:12Z</dc:date>
    </item>
  </channel>
</rss>

