<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are application logs not getting indexed in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629447#M218655</link>
    <description>&lt;P&gt;The internal logs flow to splunk UI but the applications logs are not flowing to splunk UI.&lt;BR /&gt;&lt;BR /&gt;We have a cluster with several different components. We are facing the above issue with only one of the component, although, the splunk configuration for all the components are same except the host differs.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2023 15:56:47 GMT</pubDate>
    <dc:creator>amand</dc:creator>
    <dc:date>2023-02-03T15:56:47Z</dc:date>
    <item>
      <title>Why are application logs not getting indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629447#M218655</link>
      <description>&lt;P&gt;The internal logs flow to splunk UI but the applications logs are not flowing to splunk UI.&lt;BR /&gt;&lt;BR /&gt;We have a cluster with several different components. We are facing the above issue with only one of the component, although, the splunk configuration for all the components are same except the host differs.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 15:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629447#M218655</guid>
      <dc:creator>amand</dc:creator>
      <dc:date>2023-02-03T15:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logs not getting indexed in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629449#M218656</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253526"&gt;@amand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you better describe your issue?&lt;/P&gt;&lt;P&gt;are you speking of one specific server or the issue is on all servers.&lt;/P&gt;&lt;P&gt;if on a specific server, which role has this server?&lt;/P&gt;&lt;P&gt;could you better describe your architecture? have you clusters?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 07:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629449#M218656</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-03T07:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logs not getting indexed in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629452#M218659</link>
      <description>&lt;P&gt;We have 3 components in our cluster, assume A, B, C.&lt;BR /&gt;All have been configured in the same manner.&lt;BR /&gt;But we see application logs for B &amp;amp; C but not for A.&lt;BR /&gt;Although, we are able to see _internal index logs for A.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 07:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629452#M218659</guid>
      <dc:creator>amand</dc:creator>
      <dc:date>2023-02-03T07:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logs not getting indexed in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629454#M218661</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253526"&gt;@amand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you're speaking of an Indexer Cluster and you distributed an add-on using the Master Node to all the peers.&lt;/P&gt;&lt;P&gt;Which are the application logs you're speaking of?&lt;/P&gt;&lt;P&gt;which is the add-on you're using?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 07:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629454#M218661</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-03T07:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logs not getting indexed in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629458#M218665</link>
      <description>&lt;P&gt;We are able to see this on UI :&amp;nbsp;&lt;STRONG&gt;index=_internal host=ip-xx-xx-xx-xxx source="/opt/splunkforwarder/var/log/splunk/splunkd.log"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but not this :&amp;nbsp;&lt;STRONG&gt;index="blitz-athena" host=ip-xx-xx-xx-xxx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;source = "/var/log/supervisord/collector.log"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S&amp;nbsp; : These two indexes are of the same host&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 07:54:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629458#M218665</guid>
      <dc:creator>amand</dc:creator>
      <dc:date>2023-02-03T07:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logs not getting indexed in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629477#M218671</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253526"&gt;@amand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;can you see other events on the same index?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 10:56:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-application-logs-not-getting-indexed-in-Splunk/m-p/629477#M218671</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-03T10:56:20Z</dc:date>
    </item>
  </channel>
</rss>

