<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to find sourcetype in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/661023#M54400</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 13:39:18 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-10-17T13:39:18Z</dc:date>
    <item>
      <title>Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660828#M54377</link>
      <description>&lt;P&gt;Will i am seeing the events data is showing but there is sourcetype is missing for last 24 hours.&lt;BR /&gt;&lt;BR /&gt;What could be the reason , how to check .&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 09:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660828#M54377</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2023-10-16T09:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660837#M54378</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if one sourcetype was present and noy it's missing, there could be two reasons:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you modified the inputs.conf assigning the sourcetype to a data flow,&lt;/LI&gt;&lt;LI&gt;the data flow stopped.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You can check the first choice viewing if someone modified the inputs.conf that should ingest data.&lt;/P&gt;&lt;P&gt;For the second choice you should analyze, if you're still receiving data and when the data stopped:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index sourcetype=your_sourcetype
| head 10&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 10:42:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660837#M54378</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-16T10:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660839#M54379</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for your reply , but the data is visible like in 7 days it will be like 6 days visible 1 day missing or 5 days visible 2 days missing vice-versa .&lt;BR /&gt;&lt;BR /&gt;what could be solution for that&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 10:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660839#M54379</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2023-10-16T10:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660843#M54381</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should create an alert when data flow stopped and immediately see if there something that blocked it.&lt;/P&gt;&lt;P&gt;then, if the data flow arrives from text files, you could see if in the files there are data in the missing periods.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 10:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660843#M54381</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-16T10:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660876#M54383</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No Recent Logs Found for Source: abc:conf&lt;BR /&gt;No Splunk ingestion for Glo_Pa Alxt Ingestion found in the last 24 hours for:&lt;BR /&gt;Index: glo_pa_logs&lt;BR /&gt;SourceType: abc:conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to find in SSH or in UI&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 14:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660876#M54383</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2023-10-16T14:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660896#M54387</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;P&gt;if you run this search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=glo_pa_logs sourceType=abc:conf &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;in the last 24 hours, have you results?&lt;/P&gt;&lt;P&gt;have you results in the last 7 days?&lt;/P&gt;&lt;P&gt;running this search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=glo_pa_logs sourceType=abc:conf 
| timechart span=1h count&lt;/LI-CODE&gt;&lt;P&gt;what are the results?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660896#M54387</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-16T16:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660909#M54389</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Have a look in the ss able to see the data for last few days but not for last 3 days ,how to check that what is happen to the data for last 3 days .&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Praz_123_2-1697475399343.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27599iCADF73EC568AD33B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Praz_123_2-1697475399343.png" alt="Praz_123_2-1697475399343.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Praz_123_1-1697475178019.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27598i297AF7D500C7A93F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Praz_123_1-1697475178019.png" alt="Praz_123_1-1697475178019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660909#M54389</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2023-10-16T16:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660968#M54396</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;how do you read the logs? are they in a file?&lt;/P&gt;&lt;P&gt;if yes, check if in the file there are logs in the missing periods.&lt;/P&gt;&lt;P&gt;if not, the issue is outside Splunk.&lt;/P&gt;&lt;P&gt;If yes, your should check if they were writtend moment by moment or after a delay.&lt;/P&gt;&lt;P&gt;For this reason I hint to create an alert depending on the update frequency of your data&amp;nbsp;(e.g. every 15 minutes).&lt;/P&gt;&lt;P&gt;So you can immediately check if the issue is in Splunk or outside it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 06:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/660968#M54396</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T06:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/661022#M54399</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for support &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/661022#M54399</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2023-10-17T13:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find sourcetype</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/661023#M54400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-able-to-find-sourcetype/m-p/661023#M54400</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T13:39:18Z</dc:date>
    </item>
  </channel>
</rss>

