<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: .kvp file forwarding from the server but not appearing in Splunk Indexer in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289777#M18386</link>
    <description>&lt;P&gt;Hi Richgalloway,&lt;/P&gt;

&lt;P&gt;How we will check whether SSL expired or not in Splunk forwarder ? If it is expired, how we will get renewal this ? We install forwarder downloading from Splunk.com .&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 17:26:18 GMT</pubDate>
    <dc:creator>RAYUDU_NARA</dc:creator>
    <dc:date>2017-07-05T17:26:18Z</dc:date>
    <item>
      <title>.kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289775#M18384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Suddenly data not appearing in the indexer and dash board but it is forwarding from the server. No configuration changed but earlier it is forwarding and stopped suddenly at end of the month at last hour.&lt;/P&gt;

&lt;P&gt;Is there any Indexer configuration limit or what is the issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 16:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289775#M18384</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-05T16:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289776#M18385</link>
      <description>&lt;P&gt;Are you using SSL?  That the forwarding stopped at the end of the month makes me think a certificate expired.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289776#M18385</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-05T17:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289777#M18386</link>
      <description>&lt;P&gt;Hi Richgalloway,&lt;/P&gt;

&lt;P&gt;How we will check whether SSL expired or not in Splunk forwarder ? If it is expired, how we will get renewal this ? We install forwarder downloading from Splunk.com .&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289777#M18386</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-05T17:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289778#M18387</link>
      <description>&lt;P&gt;If you or your admin did not specifically set up SSL then you are not using it.&lt;BR /&gt;
That means something else changed at the end of the month.  Perhaps someone pushed out a firewall change before leaving on Friday.&lt;BR /&gt;
Have you checked Splunk's logs?  Maybe something is preventing it from writing to the index.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 18:29:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289778#M18387</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-05T18:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289779#M18388</link>
      <description>&lt;P&gt;Hi Richgalloway,&lt;/P&gt;

&lt;P&gt;This issue in windows forwarder.&lt;/P&gt;

&lt;P&gt;.kvp file forwarding if we place without timestamp in the file.&lt;BR /&gt;
But same file if we place with timestamp it is forwarding but not appearing in Splunk.&lt;BR /&gt;
But from the server all Splunk logs, metric logs, system event logs everything appearing. Only script data is not appearing in Splunk indexer.&lt;/P&gt;

&lt;P&gt;appearing:   number_of_Images=20&lt;BR /&gt;
not appearing : timestamp="06/07/2017 13:26:05" number_of_Images=20&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289779#M18388</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2020-09-29T14:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289780#M18389</link>
      <description>&lt;P&gt;What are your props.conf settings for that file's sourcetype?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 12:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289780#M18389</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-06T12:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289781#M18390</link>
      <description>&lt;P&gt;Mmmm, the events stopped indexing at the end of the month. I suspect there may be a timestamp mismatch and the events for 1st July were indexed with a date of 7th January, the events for 2nd July were indexed with a date of 7th February.  Will these events magically start indexing tonight at midnight?&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 12:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289781#M18390</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2017-07-06T12:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289782#M18391</link>
      <description>&lt;P&gt;Yes Dave, last month same issue. stopped at 31st may midnight 11pm and started at 6th june 12am. But this month stopped at 11pm june but started yet.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289782#M18391</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-06T13:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289783#M18392</link>
      <description>&lt;P&gt;The documentation covers &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Data/Configuretimestamprecognition"&gt;timestamp recognition&lt;/A&gt;. I suspect you will need to specifically define a TIME_FORMAT attribute for this data, so that Splunk can correctly interpret the timestamp in the event.&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 14:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289783#M18392</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2017-07-06T14:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289784#M18393</link>
      <description>&lt;P&gt;Hi Dave,&lt;BR /&gt;
Like below we are data forwarding and appearing in Splunk indexer.&lt;/P&gt;

&lt;P&gt;data stopped at 11pm end of the month  and started at 12am like below.&lt;/P&gt;

&lt;P&gt;Feb - 1st no data                      , from 2nd we have data&lt;BR /&gt;
Mar - 1st and 2nd no data      , From 3rd we have data&lt;BR /&gt;
April - 1st - 3rd no data           , from 4th we have data&lt;BR /&gt;
May - 1st - 4th no data            , from 5th we have data&lt;BR /&gt;
June - 1st - 5th no data,          , from 6th we have data&lt;BR /&gt;
July - 1st - 6th no data –          hope we have data from this mid night 12am&lt;/P&gt;

&lt;P&gt;Here how we can fix the issue, this is in Production Environment.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 17:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289784#M18393</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-06T17:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289785#M18394</link>
      <description>&lt;P&gt;I think @davebrooking has hit the nail on the head.  Splunk defaults to US date format (mm/dd/yyyy) and is easily confused by dd/mm/yyyy dates.  The best fix, which really should be done by everyone for every sourcetype, is to specify a TIME_FORMAT attribute in props.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 20:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289785#M18394</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-06T20:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289786#M18395</link>
      <description>&lt;P&gt;Hi richgalloway,&lt;/P&gt;

&lt;P&gt;Is the TIME_FORMAT we need to change to mm/dd/yyyy or dd/mm/yyyy ?&lt;/P&gt;

&lt;P&gt;my soucename is Import_Count-kvp, so need to place in the props.conf like below,&lt;/P&gt;

&lt;P&gt;[Import_Count-kvp]&lt;BR /&gt;
TIME_FORMAT=mm/dd/yyy&lt;/P&gt;

&lt;P&gt;And in one server we don't have source name we are monitoring with Indexer name splunk, so for this props.conf like,&lt;/P&gt;

&lt;P&gt;[splunk]&lt;BR /&gt;
TIME_FORMAT=mm/dd/yyy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289786#M18395</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2020-09-29T14:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289787#M18396</link>
      <description>&lt;P&gt;Use &lt;CODE&gt;TIME_FORMAT = %d/%m/%Y&lt;/CODE&gt;, assuming your dates are in that format (day/month/year).&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 12:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289787#M18396</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-07T12:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289788#M18397</link>
      <description>&lt;P&gt;time format is correct but It is not working richgalloway.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 16:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289788#M18397</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-07T16:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289789#M18398</link>
      <description>&lt;P&gt;Is this configuration need to be done at forwarder level or Indexer level ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 13:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289789#M18398</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-10T13:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289790#M18399</link>
      <description>&lt;P&gt;The indexer level. &lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 15:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289790#M18399</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-10T15:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: .kvp file forwarding from the server but not appearing in Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289791#M18400</link>
      <description>&lt;P&gt;Hi Richgalloway,&lt;/P&gt;

&lt;P&gt;It is working fine now. Thank you.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Rayudu&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 11:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/kvp-file-forwarding-from-the-server-but-not-appearing-in-Splunk/m-p/289791#M18400</guid>
      <dc:creator>RAYUDU_NARA</dc:creator>
      <dc:date>2017-07-25T11:57:23Z</dc:date>
    </item>
  </channel>
</rss>

