<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder - Not Forwarding Data - Intermittent Issue in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602072#M209560</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/65114"&gt;@madhav_dholakia&lt;/a&gt;&amp;nbsp;- Your configuration looks correct to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you should observe how your system is overriding the data in the CSV files every time, how and when they are writing in the file, what is the size of the files, and how long it's taking to write a file.&lt;/P&gt;&lt;P&gt;Please monitor the above parameters on the host for files which are having this more than other files and compare. I think that should lead you to the root cause that is causing this intermittent issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 13:08:54 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-06-16T13:08:54Z</dc:date>
    <item>
      <title>Universal Forwarder - Not Forwarding Data - Intermittent Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602054#M209549</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;Hi All,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;We have a universal forwarder running on Windows Server which is sending data to our Splunk Instance in Cloud.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Below are some details of .conf files and logs:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[default]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;host = DB_DATA&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[monitor://D:\ABC\DB_Monitoring\Cust]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;disabled=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;index=rjsql&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sourcetype = csv&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;time_before_close = 60&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[default]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;NO_BINARY_CHECK=true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;CHARSET=AUTO&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[source::D:\ABC\DB_Monitoring\Cust\*.csv]&lt;BR /&gt;CHECK_METHOD = modtime&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;There are some files which are either 1) no being indexed at all 2) only headers are indexed - this doesn't happen with all the files, only some of them.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Logs from _internal (for file which has got only header indexed)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="madhav_dholakia_1-1655378730697.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20125iAD43B523110C833B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="madhav_dholakia_1-1655378730697.png" alt="madhav_dholakia_1-1655378730697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Tailing processer file status&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="madhav_dholakia_2-1655378896371.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20126iD1DFDCC55DECC55E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="madhav_dholakia_2-1655378896371.png" alt="madhav_dholakia_2-1655378896371.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;btool output:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="madhav_dholakia_3-1655379120242.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20127iA230FB832D99DE7D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="madhav_dholakia_3-1655379120242.png" alt="madhav_dholakia_3-1655379120242.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can you please suggest what else I could check here and resolve this intermittent issue?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 11:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602054#M209549</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-06-16T11:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Not Forwarding Data - Intermittent Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602072#M209560</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/65114"&gt;@madhav_dholakia&lt;/a&gt;&amp;nbsp;- Your configuration looks correct to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you should observe how your system is overriding the data in the CSV files every time, how and when they are writing in the file, what is the size of the files, and how long it's taking to write a file.&lt;/P&gt;&lt;P&gt;Please monitor the above parameters on the host for files which are having this more than other files and compare. I think that should lead you to the root cause that is causing this intermittent issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602072#M209560</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-06-16T13:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Not Forwarding Data - Intermittent Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602078#M209562</link>
      <description>&lt;P&gt;thanks,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;- these files are &amp;lt;10KBs and updated every 15 days/month. With a time_before_close param set, I don't think file writing will take more time looking at the file size.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602078#M209562</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-06-16T13:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Not Forwarding Data - Intermittent Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602085#M209567</link>
      <description>&lt;P&gt;Yeah, file size, I don't think should be a problem here then.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Universal-Forwarder-Not-Forwarding-Data-Intermittent-Issue/m-p/602085#M209567</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-06-16T13:51:26Z</dc:date>
    </item>
  </channel>
</rss>

