<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I  not receiving  /var/log/messages from the Linux Server in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/543727#M4870</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is the server is red hat or Ubuntu?&lt;/P&gt;&lt;P&gt;Can you check is there any extension after messages like mesages.log?&lt;/P&gt;&lt;P&gt;Is there any error in splunkd.log?&lt;/P&gt;&lt;P&gt;If everything is right can you remove the blacklist and&amp;nbsp;&lt;SPAN&gt;ignoreOlderThan from the stanza and restart the forwarder and check again.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Mar 2021 12:40:41 GMT</pubDate>
    <dc:creator>Vardhan</dc:creator>
    <dc:date>2021-03-14T12:40:41Z</dc:date>
    <item>
      <title>I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/543723#M4869</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not receiving the &lt;STRONG&gt;/var/log/messages&lt;/STRONG&gt; from linux server.&amp;nbsp; I have written the stanza to monitored the &lt;STRONG&gt;var/log/massages&lt;/STRONG&gt; in inputs.conf , Although receiving the &lt;STRONG&gt;var/log/audit.lo&lt;/STRONG&gt;g and /&lt;STRONG&gt;var/log/secure.log,&lt;/STRONG&gt; also given the read permission to splunk user for &lt;STRONG&gt;var/log&lt;/STRONG&gt;&amp;nbsp;directory .&amp;nbsp; And&amp;nbsp; mesage logs are generating continuously&amp;nbsp; at the remote side but still not receiving message logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///var/log/messages]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = linux&lt;BR /&gt;blacklist = .*csv$&lt;BR /&gt;ignoreOlderThan = 1d&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 12:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/543723#M4869</guid>
      <dc:creator>Pavankumar</dc:creator>
      <dc:date>2021-03-14T12:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/543727#M4870</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is the server is red hat or Ubuntu?&lt;/P&gt;&lt;P&gt;Can you check is there any extension after messages like mesages.log?&lt;/P&gt;&lt;P&gt;Is there any error in splunkd.log?&lt;/P&gt;&lt;P&gt;If everything is right can you remove the blacklist and&amp;nbsp;&lt;SPAN&gt;ignoreOlderThan from the stanza and restart the forwarder and check again.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 12:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/543727#M4870</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-14T12:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545260#M4923</link>
      <description>&lt;P&gt;I am facing this issue on Linux machine (red hat and centos )&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;there any&amp;nbsp; no extension after messages&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 05:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545260#M4923</guid>
      <dc:creator>Pavankumar</dc:creator>
      <dc:date>2021-03-25T05:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545316#M4924</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232468"&gt;@Pavankumar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;1)Can you run the command &lt;STRONG&gt;./splunk list inputstatus&lt;/STRONG&gt; and check the status for /var/log/messages&lt;/P&gt;&lt;P&gt;2) Is there any error in Splunkd.log?&lt;/P&gt;&lt;P&gt;go to /opt/splunkforwarder/var/log/splunk&lt;/P&gt;&lt;P&gt;cat splunkd.log | grep -i error&amp;nbsp; &amp;nbsp; &amp;nbsp;(check for any errors)&lt;/P&gt;&lt;P&gt;3)Did u restarted the forwarder after deploying the config? And did u check the permissions are the same for /var/log/secure and /var/log/messages?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 10:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545316#M4924</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-25T10:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545344#M4925</link>
      <description>&lt;P&gt;If you are running UF as splunk user you should check that this user has read access to this (and other needed logs). Quite often those needs to grant separately.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 10:59:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/545344#M4925</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-03-25T10:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/546325#M4948</link>
      <description>&lt;P&gt;I have receiving log through host name in some servers messages.log not receiving &lt;SPAN&gt;&amp;nbsp;Although receiving the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;var/log/audit.lo&lt;/STRONG&gt;&lt;SPAN&gt;g and /&lt;/SPAN&gt;&lt;STRONG&gt;var/log/secure.log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;but in some server facing issue like&amp;nbsp; if the host name is for example "&lt;STRONG&gt;test.ab.co.in&lt;/STRONG&gt; " when checking log though&amp;nbsp;&lt;STRONG&gt; host=&amp;nbsp;test.ab.co.in&amp;nbsp;&lt;/STRONG&gt;then received&amp;nbsp;&lt;STRONG&gt;var/log/audit.lo&lt;/STRONG&gt;&lt;SPAN&gt;g and /&lt;/SPAN&gt;&lt;STRONG&gt;var/log/secure.log.&amp;nbsp; Not receiving&amp;nbsp; Messages log .&amp;nbsp; But&amp;nbsp;&lt;/STRONG&gt;when searching&amp;nbsp; &lt;STRONG&gt;host=test&amp;nbsp; then I can receiving Messages log..&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 05:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/546325#M4948</guid>
      <dc:creator>Pavankumar</dc:creator>
      <dc:date>2021-04-01T05:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: I  not receiving  /var/log/messages from the Linux Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/546398#M4950</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;what you will get with commands hostname and uname -a ?&lt;/P&gt;&lt;P&gt;you could add host = &amp;lt;your hostname&amp;gt; to inputs.conf if needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 16:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/I-not-receiving-var-log-messages-from-the-Linux-Server/m-p/546398#M4950</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-04-01T16:55:42Z</dc:date>
    </item>
  </channel>
</rss>

