<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not receiving data from particular source in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628730#M218400</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;how can i check that, can u please tell me????&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jan 2023 01:52:31 GMT</pubDate>
    <dc:creator>Harish2</dc:creator>
    <dc:date>2023-01-29T01:52:31Z</dc:date>
    <item>
      <title>Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628727#M218397</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;My sources:&lt;BR /&gt;1.&amp;nbsp; /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC.log&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-show.log&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-ignored-sms.log&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; /app/splunkser/ShiftMinJMC/ShiftMinJMC.log&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; /app/splunkser/ShiftMinJMC/ShiftMinJMC-show.log&lt;/P&gt;&lt;P&gt;6.&amp;nbsp; /app/splunkser/ShiftMinJMC/ShiftMinJMC-ignored-sms.log&lt;/P&gt;&lt;P&gt;7.&amp;nbsp; /app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC.log&lt;/P&gt;&lt;P&gt;8.&amp;nbsp; /app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC-show.log&lt;/P&gt;&lt;P&gt;9.&amp;nbsp; /app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC-ignored-sms.log&lt;/P&gt;&lt;P&gt;I am receive the data from the above sources in SIT&amp;nbsp; and PROD environment but not receiving&amp;nbsp; logs from the below sources:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC.log&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; /app/splunkser/ShiftMinJMC/ShiftMinJMC.log&lt;/P&gt;&lt;P&gt;7.&amp;nbsp; /app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC.log&lt;BR /&gt;&lt;BR /&gt;Note: i am getting logs in SIT from all 9 sources but in production the mentioned 1, 4 and 7th sources are not showing up in Production env.&lt;BR /&gt;&lt;BR /&gt;Inputs.conf&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-show-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-ignored-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftMinJMC/ShiftMinJMC-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftMinJMC/ShiftMinJMC-show-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftMinJMC/ShiftMinJMC-ignored-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC-show-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:///app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC-ignored-*.log]&lt;BR /&gt;disabled=0&lt;BR /&gt;index=app-jmc-shift-sms&lt;BR /&gt;sourcetype=app:jmcshift:logs&lt;BR /&gt;blacklist=\.(?:tar|gz)$&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Props.conf&lt;/P&gt;&lt;P&gt;[app:jmcshift:logs]&lt;BR /&gt;TIME_PREFIX=^&lt;BR /&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=30&lt;BR /&gt;LINE_BREAKER=([\r\n]+)\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}.\d{3}&lt;BR /&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;TRUNCATE=99999&lt;/P&gt;&lt;P&gt;Sample logs:&lt;BR /&gt;From all 9 sources the events starts with date as shown below:&lt;BR /&gt;2023-01-12 23:24:50.245 [error]...........................................&lt;BR /&gt;&lt;BR /&gt;Same inputs.cong and props.conf&amp;nbsp; in SIT and Production env.&lt;BR /&gt;Not sure what could be the issue.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 20:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628727#M218397</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-28T20:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628729#M218399</link>
      <description>&lt;P&gt;Have you checked the permissions on the missing sources to make sure Splunk has read access?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 01:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628729#M218399</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-29T01:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628730#M218400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;how can i check that, can u please tell me????&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 01:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628730#M218400</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-29T01:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628731#M218401</link>
      <description>&lt;P&gt;Sign on to the source server and run&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ls -ls /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC.log /app/splunkser/ShiftMinJMC/ShiftMinJMC.log /app/splunkser/ShiftBDRecordJMC/ShiftBDRecordJMC.log&lt;/LI-CODE&gt;&lt;P&gt;This will tell you who owns the files and the groups which can access it.&amp;nbsp; Use the groups command to find out the groups to which the Splunk user belongs.&amp;nbsp; Contact your Linux admin for specific assistance.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 03:42:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628731#M218401</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-29T03:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628754#M218410</link>
      <description>&lt;P&gt;I checked there is no permission issue, i can see other files with the same permission.&lt;/P&gt;&lt;P&gt;But not able to see data from mentioned sources&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 14:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628754#M218410</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-29T14:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data from particular source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628760#M218411</link>
      <description>&lt;P&gt;Here are a few other things to check.&lt;/P&gt;&lt;P&gt;Look in splunkd.log on the forwarders to see if there are messages about reading those sources.&lt;/P&gt;&lt;P&gt;If you use SELinux, have someone verify the settings allow Splunk to read the sources.&amp;nbsp; If you can sign in as the Splunk user and read the files then Splunk itself should be able to read them.&lt;/P&gt;&lt;P&gt;Verify the sources are going to the right indexes.&lt;/P&gt;&lt;P&gt;Verify the timestamps in the sources are being onboarded correctly.&amp;nbsp; Incorrect timestamps could make it hard to find data from the source.&amp;nbsp; Try searching with &lt;FONT face="courier new,courier"&gt;earliest=0 latest=+1y&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;Double-check the SPL used to search for the sources.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 16:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-from-particular-source/m-p/628760#M218411</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-29T16:57:36Z</dc:date>
    </item>
  </channel>
</rss>

