<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing data on ingest in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654855#M226215</link>
    <description>&lt;P&gt;We have root running splunkd on all our UFs with no issues.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2023 12:51:56 GMT</pubDate>
    <dc:creator>ReginaP</dc:creator>
    <dc:date>2023-08-18T12:51:56Z</dc:date>
    <item>
      <title>Why is there Missing data on ingestion?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654775#M226190</link>
      <description>&lt;P&gt;Brand news servers. Not receiving all data from the UF.&lt;BR /&gt;Confirmed connectivity.&lt;BR /&gt;Confirmed inputs via "/opt/splunkforwarder/bin/splunk btool inputs list | grep bc_ | grep "\["",&lt;BR /&gt;Only getting 2 sourcetypes when there should be at least 16 for the index.&lt;BR /&gt;&lt;BR /&gt;Getting this error message:&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).&lt;BR /&gt;&lt;BR /&gt;Getting this when starting splunkd:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Splunk&amp;gt; Take the sh out of IT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking prerequisites...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Management port has been set disabled; cli support for this configuration is currently incomplete.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checking conf files for problems...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Done&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checking default conf files for edits...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Validating installed files against hashes from '/opt/splunkforwarder/splunkforwarder-9.0.3-dd0128b1f8cd-linux-2.6-x86_64-manifest'&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All installed files intact.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Done&lt;BR /&gt;All preliminary checks passed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;Done&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 18:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654775#M226190</guid>
      <dc:creator>ReginaP</dc:creator>
      <dc:date>2023-08-18T18:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654805#M226196</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251903"&gt;@ReginaP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you disabled the local firewall on the system?&lt;/P&gt;&lt;P&gt;did you checked the connectivity between the forwarder and the Indexer using telnet on the port you configure for receiving?&lt;/P&gt;&lt;P&gt;did you enabled receiving on the Indexers?&lt;/P&gt;&lt;P&gt;the "&lt;SPAN&gt;Invalid key" error isn't relevant, is instead very strange the message "Management port has been set disabled; cli support for this configuration is currently incomplete".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;for the second message, you could see the solution at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386916" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386916&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;but anyway, iy shouldn't have effects on the log forwarding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 07:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654805#M226196</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-18T07:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654834#M226208</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;which user you are running splunkd on UF? You should use separate non root user. But this means that you must give access to this user to access those files which you want to read. You should try to check if user have access those e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo -s root bash
sudo -s &amp;lt;your splunk user&amp;gt; bash
less /path/to/log/file&lt;/LI-CODE&gt;&lt;P&gt;If you cannot see the content of that file you need to give access by e.g. "setfacl" command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 09:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654834#M226208</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T09:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654855#M226215</link>
      <description>&lt;P&gt;We have root running splunkd on all our UFs with no issues.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:51:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654855#M226215</guid>
      <dc:creator>ReginaP</dc:creator>
      <dc:date>2023-08-18T12:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654857#M226216</link>
      <description>&lt;P&gt;I checked the connection via telnet to the correct port.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:58:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654857#M226216</guid>
      <dc:creator>ReginaP</dc:creator>
      <dc:date>2023-08-18T12:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654863#M226219</link>
      <description>&lt;P&gt;Actually this is huge security issue, but it shouldn't affect to your current issue.&lt;/P&gt;&lt;P&gt;When you do that "splunk btool inputs ...." you get 16+ sourcetypes of inputs, but on splunk there is only 2 of them?&lt;/P&gt;&lt;P&gt;What you get with&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk list inputstatus&lt;/LI-CODE&gt;&lt;P&gt;For your missing bc_* inputs? There should be something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/your/input/file/bc_something
	file position = 631
	file size = 631
	parent = /var/log
	percent = 100.00
	type = finished reading&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 18 Aug 2023 13:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654863#M226219</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T13:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Missing data on ingest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654926#M226241</link>
      <description>&lt;P&gt;It was a RHEL8 python issue. Thank you for your responses&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 18:04:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-Missing-data-on-ingestion/m-p/654926#M226241</guid>
      <dc:creator>ReginaP</dc:creator>
      <dc:date>2023-08-18T18:04:59Z</dc:date>
    </item>
  </channel>
</rss>

