<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208364#M60771</link>
    <description>&lt;P&gt;This forwarder is a Windows. How to check this on this OS please ? Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jul 2016 09:16:38 GMT</pubDate>
    <dc:creator>kemmlli</dc:creator>
    <dc:date>2016-07-07T09:16:38Z</dc:date>
    <item>
      <title>I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208360#M60767</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm evaluating Splunk for the first time. I installed a forwarder on a Windows server and I configured the inputs.conf (/etc/system/local) like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = name1

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[monitor://C:\Program Files (x86)\FileZilla Server\Logs\]
host = name1
index=FTP_logs_2
source="C:\Program Files (x86)\FileZilla Server\Logs\"
disabled = 0
whitelist=.log$
#ignoreOlderThan = 7d
#blacklist=C:\logs\onelog.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The goal is to monitor FileZilla logs.&lt;BR /&gt;
Index has been created on indexer.&lt;/P&gt;

&lt;P&gt;When I'm trying to search data by typing name1 on the Splunk search bar, I get no data. name1 is also not on the host tab in Data Summary button. I need first to search the index in order to see data and search with a random word for finding what I want.&lt;/P&gt;

&lt;P&gt;Can anyone help me ?&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 08:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208360#M60767</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-06-14T08:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208361#M60768</link>
      <description>&lt;P&gt;Are you the only user on your system? Is your role able to search that index? &lt;/P&gt;

&lt;P&gt;You should also make sure to define the sourcetype that you're interested in in your inputs.conf stanza.&lt;/P&gt;

&lt;P&gt;Lastly is there a reason for using the whitelist setting? Are there some logs in that directory you're not interested in?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208361#M60768</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-06-14T13:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208362#M60769</link>
      <description>&lt;P&gt;On the forwarder try running the command from the splunk folder  &lt;EM&gt;bin/splunk list forward-server&lt;/EM&gt;&lt;BR /&gt;
Does it say that the connection between the forwarder and the Splunk server is active?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208362#M60769</guid>
      <dc:creator>craigv_splunk</dc:creator>
      <dc:date>2016-06-14T13:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208363#M60770</link>
      <description>&lt;P&gt;What do you see when you search for &lt;CODE&gt;host=name1&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208363#M60770</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-06-14T13:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208364#M60771</link>
      <description>&lt;P&gt;This forwarder is a Windows. How to check this on this OS please ? Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 09:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208364#M60771</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-07T09:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208365#M60772</link>
      <description>&lt;P&gt;I see "No results found" &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 09:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208365#M60772</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-07T09:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208366#M60773</link>
      <description>&lt;P&gt;I'm the only user and I'm with the default admin account.&lt;/P&gt;

&lt;P&gt;I tried whitelist to troubleshoot but its not effective.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 09:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208366#M60773</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-07T09:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208367#M60774</link>
      <description>&lt;P&gt;If you search for index=_internal, do you see any events from the host?  If not look at the logs on the forwarder, these will be in %SPLUNK_HOME%\var\log\splunk. Two useful ones to start with are the splunkd.log and the metrics.log. &lt;/P&gt;

&lt;P&gt;Do you see errors in the splunkd.log? &lt;/P&gt;

&lt;P&gt;Do you see any records in the metrics.log where group=per_index_thruput, series="FTP_logs_2"?&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208367#M60774</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2020-09-29T10:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208368#M60775</link>
      <description>&lt;P&gt;Actually, I do, with the filter "index=_internal host=name1".&lt;/P&gt;

&lt;P&gt;I did not see errors in splunkd.log on the forwarder.&lt;/P&gt;

&lt;P&gt;I see records like this one on metrics.log :&lt;BR /&gt;
"07-07-2016 10:59:23.448 +0200 INFO  Metrics - group=per_index_thruput, series="ftp_logs_2", kbps=1.134435, eps=1.290304, kb=35.167969, ev=40, avg_age=375332.150000, max_age=1073997"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208368#M60775</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2020-09-29T10:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208369#M60776</link>
      <description>&lt;P&gt;OK, the mettrics.log events indicate that the file is being monitored. The search indicates that the forwarder is sending events to the indexer as expected.&lt;/P&gt;

&lt;P&gt;If you enter the search &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=FTP_logs_2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;do you see any events?&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 10:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208369#M60776</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2016-07-07T10:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208370#M60777</link>
      <description>&lt;P&gt;I do. It's the only way I founded to retrieve data from this input.&lt;BR /&gt;
At this step, filter is "index=FTP_logs_2".&lt;/P&gt;

&lt;P&gt;If I add "host=name1" in order to obtain "index=FTP_logs_2 host=name1" as a filter, I get the same results. But if I only add "host=name1", I do not obtain results. Don't know if this helps.&lt;/P&gt;

&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208370#M60777</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2020-09-29T10:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208371#M60778</link>
      <description>&lt;P&gt;By default Splunk will only search the main index. You can add extra default  indexes to different roles from Settings &amp;gt; Access controls &amp;gt; Roles select the appropriate role, and in the section "Indexes searched by default" add the index FTP_logs_2.&lt;/P&gt;

&lt;P&gt;However, the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Search/Writebettersearches#Restrict_searches_to_the_specific_index" target="_blank"&gt;search manual&lt;/A&gt; states for efficient searches you should be more specific, adding indexes in this way will search through more data&lt;/P&gt;

&lt;P&gt;Dave &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208371#M60778</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2020-09-29T10:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208372#M60779</link>
      <description>&lt;P&gt;Indeed ! It works !&lt;/P&gt;

&lt;P&gt;Thank you all !&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 12:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208372#M60779</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-07T12:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208373#M60780</link>
      <description>&lt;P&gt;From a cmd prompt, run&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\bin\splunk list forward-server
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or also from cmd&lt;BR /&gt;
change to drive C: if it isn't already.&lt;BR /&gt;
cd into &lt;CODE&gt;\Program Files\SplunkUniversalForwarder\bin&lt;/CODE&gt;&lt;BR /&gt;
type &lt;CODE&gt;splunk list forward-server&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 13:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208373#M60780</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-07-07T13:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208374#M60781</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;

&lt;P&gt;I noticed just one thing : my host name1 is still not on the host list in the Data summary. Any ideas ?&lt;/P&gt;

&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 11:32:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208374#M60781</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-08T11:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208375#M60782</link>
      <description>&lt;P&gt;Is the index that your host is in set to be searched by default in Your user's role?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 22:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208375#M60782</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-07-08T22:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: I've configured inputs.conf for a Splunk forwarder on Windows, but why do I get no data searching for that host?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208376#M60783</link>
      <description>&lt;P&gt;It was not, now it's ok !&lt;/P&gt;

&lt;P&gt;Thanks again guys !&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 08:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-ve-configured-inputs-conf-for-a-Splunk-forwarder-on-Windows/m-p/208376#M60783</guid>
      <dc:creator>kemmlli</dc:creator>
      <dc:date>2016-07-11T08:14:34Z</dc:date>
    </item>
  </channel>
</rss>

