<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Receiving data from particular source in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/608357#M211521</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211432"&gt;@jamie00171&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what you said is correct about the follow tail=1, when i removed it, i can see the source which was missing before.&lt;BR /&gt;It really helped me a lot, thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 21:53:25 GMT</pubDate>
    <dc:creator>Vani_26</dc:creator>
    <dc:date>2022-08-04T21:53:25Z</dc:date>
    <item>
      <title>Why am I not receiving data from particular source?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607592#M211258</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; I have 4 sources from one sourcetype . so i am getting data from 3 sources but not from other 1 source.&lt;BR /&gt;&lt;BR /&gt;Logs are present , but not showing up in splunk.&lt;BR /&gt;checked inputs.conf&amp;nbsp; everything is--same configuration for all 4 sources.&lt;BR /&gt;crccsalt=source&amp;nbsp; is also there in inputs.config.&lt;BR /&gt;restarted the servers, but still not able to see the data&lt;BR /&gt;&lt;BR /&gt;Can you please tell me anything i am missing.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 22:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607592#M211258</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-07-30T22:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607598#M211260</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248147"&gt;@Vani_26&lt;/a&gt;&amp;nbsp;... we may need some more details please..&lt;/P&gt;&lt;P&gt;1. Approx when all these 4 logs are added to splunk? (recently or long back?)&lt;/P&gt;&lt;P&gt;2. Any recent changes in Splunk environment? are you using HF?&lt;/P&gt;&lt;P&gt;3. Are these 4 logs are same type? i mean, simple file monitoring or what these 4 sources pls&lt;/P&gt;&lt;P&gt;4. on the internal logs, do you see any errors, warnings pls.&lt;/P&gt;&lt;P&gt;5. these 4 logs are there locally on Splunk system or you have UF reading these logs and then sending them to indexer?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 06:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607598#M211260</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2022-07-30T06:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607612#M211269</link>
      <description>&lt;P&gt;1. Approx when all these 4 logs are added to splunk? (recently or long back?)&lt;BR /&gt;&lt;BR /&gt;From 3 sources logs are recent, but from other 1 source&amp;nbsp; there are logs on july1st after that no logs&amp;nbsp; and again i see logs on 29th july.&lt;/P&gt;&lt;P&gt;2. Any recent changes in Splunk environment? are you using HF?&lt;BR /&gt;&lt;BR /&gt;no changes in recent logs and i am not using HF.&lt;/P&gt;&lt;P&gt;3. Are these 4 logs are same type? i mean, simple file monitoring or what these 4 sources pls&lt;BR /&gt;All the&amp;nbsp; 4 sources logs are of below format&lt;BR /&gt;eg: 2022-07-29 12:00:31,630&amp;nbsp; hgdshgdjsjsnk........................&lt;BR /&gt;&lt;BR /&gt;and my inputs.conf is&lt;BR /&gt;[monitior: ///abc/adcd/logs/adc-adc-adc-as-ATV/*.log]&lt;BR /&gt;index=abc&lt;BR /&gt;sourcetype=abcd&lt;BR /&gt;crscSalt=&amp;lt;Source&amp;gt;&lt;BR /&gt;intCrcLength=1024&lt;BR /&gt;no_binary_check=true&lt;BR /&gt;disabled=0&lt;BR /&gt;followtail=1&lt;/P&gt;&lt;P&gt;4. on the internal logs, do you see any errors, warnings pls.&lt;BR /&gt;No error or warnings in internal logs.&lt;/P&gt;&lt;P&gt;5. these 4 logs are there locally on Splunk system or you have UF reading these logs and then sending them to indexer?&lt;BR /&gt;these all 4 sources are from UF and then sending them to indexer.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 13:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607612#M211269</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-07-30T13:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607638#M211288</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248147"&gt;@Vani_26&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From inputs.conf docs regrading "followTail"&lt;/P&gt;&lt;PRE&gt;* If you set to "1", monitoring starts at the end of the file (like
  *nix 'tail -f'). The input does not read any data that exists in
  the file when it is first encountered. The input only reads data that
  arrives after the first encounter time.&lt;/PRE&gt;&lt;P&gt;So it could be that if you create a file there then none of the initial data will be indexed. The docs also don't recommend having followTail set to 1. I think best practice would be to create a new file each time there is new data to be written to Splunk.&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jamie&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 08:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/607638#M211288</guid>
      <dc:creator>jamie00171</dc:creator>
      <dc:date>2022-07-31T08:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Not Receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/608357#M211521</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211432"&gt;@jamie00171&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what you said is correct about the follow tail=1, when i removed it, i can see the source which was missing before.&lt;BR /&gt;It really helped me a lot, thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 21:53:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-not-receiving-data-from-particular-source/m-p/608357#M211521</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-08-04T21:53:25Z</dc:date>
    </item>
  </channel>
</rss>

