<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264790#M79518</link>
    <description>&lt;P&gt;@Frederik,&lt;/P&gt;

&lt;P&gt;Let's say you have 5 machines that you want to collect xyz.log (which exists on all 5 hosts)&lt;BR /&gt;
 1. You need to have forwarders on all 5 hosts&lt;BR /&gt;
 2. On each of the 5 hosts, in inputs.conf under $SPLUNK_HOME/etc/system/local directory, host should be FQDN of that particular machine (eg, on host1, it would be host=host1) next is your monitor/batch (read inputs.conf from docs) should point to the actual log location on that host.&lt;BR /&gt;
 3. outputs.conf , since all these 5 hosts are sending to the same splunk (assumption) they can be pretty much be same on all 5 hosts. This is the typical process configuring a forwarder. &lt;/P&gt;

&lt;P&gt;With the little information provided, we can only assume what might be wrong, example.&lt;BR /&gt;
 1. As one of the answers suggested, is forwarder service up and running on all the hosts?&lt;BR /&gt;
 2. What user is your splunk forwarder running as? Does that user have Read access to the log file you are trying to consume?&lt;BR /&gt;
 3. Have you checked the connectivity from all the data sources/hosts to Central splunk instance? telnet central splunk's ip 9997? &lt;BR /&gt;
 4. Is it NAT'd or probably firewall is blocking the communication? Completely different issue &lt;/P&gt;

&lt;P&gt;What can be done is, go to the splunkd.log on the machines that are not forwarding logs (Located under $SPLUNK_HOME/var/log/ and do a tail -f splunkd.log) see any ERRORS and abnormal stuff? If yes, that would be the first step of your triage.&lt;/P&gt;

&lt;P&gt;For more accurate answers, please provide more information and ERRORS if any from your splunkd.log. Hope this helps!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2016 02:24:10 GMT</pubDate>
    <dc:creator>Raghav2384</dc:creator>
    <dc:date>2016-07-20T02:24:10Z</dc:date>
    <item>
      <title>I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264787#M79515</link>
      <description>&lt;P&gt;Sorry but this is probably a stupid question. I have set up Splunk to be able to have centralized collection of all the event logs from my servers. Now that I have installed all the agents, I cannot seem to search all the machines' event logs. I put in host=MYSERVERNAME and there are several machines that do not return anything.&lt;/P&gt;

&lt;P&gt;Does the agent need to have an app deployed to collect event logs?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 08:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264787#M79515</guid>
      <dc:creator>Frederik</dc:creator>
      <dc:date>2016-07-19T08:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264788#M79516</link>
      <description>&lt;P&gt;Can you verify that the Splunk forwarder is running on the host machines you installed it on? You can do this by going into &lt;CODE&gt;Splunk_Home/bin&lt;/CODE&gt; and run &lt;CODE&gt;./splunk status&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Also, you will need to go into &lt;CODE&gt;Splunk_Home/etc/system/local&lt;/CODE&gt; and edited the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; and make sure it's pointing to your indexer &lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 14:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264788#M79516</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-19T14:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264789#M79517</link>
      <description>&lt;P&gt;The "official" documentation at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.1/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 02:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264789#M79517</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-20T02:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264790#M79518</link>
      <description>&lt;P&gt;@Frederik,&lt;/P&gt;

&lt;P&gt;Let's say you have 5 machines that you want to collect xyz.log (which exists on all 5 hosts)&lt;BR /&gt;
 1. You need to have forwarders on all 5 hosts&lt;BR /&gt;
 2. On each of the 5 hosts, in inputs.conf under $SPLUNK_HOME/etc/system/local directory, host should be FQDN of that particular machine (eg, on host1, it would be host=host1) next is your monitor/batch (read inputs.conf from docs) should point to the actual log location on that host.&lt;BR /&gt;
 3. outputs.conf , since all these 5 hosts are sending to the same splunk (assumption) they can be pretty much be same on all 5 hosts. This is the typical process configuring a forwarder. &lt;/P&gt;

&lt;P&gt;With the little information provided, we can only assume what might be wrong, example.&lt;BR /&gt;
 1. As one of the answers suggested, is forwarder service up and running on all the hosts?&lt;BR /&gt;
 2. What user is your splunk forwarder running as? Does that user have Read access to the log file you are trying to consume?&lt;BR /&gt;
 3. Have you checked the connectivity from all the data sources/hosts to Central splunk instance? telnet central splunk's ip 9997? &lt;BR /&gt;
 4. Is it NAT'd or probably firewall is blocking the communication? Completely different issue &lt;/P&gt;

&lt;P&gt;What can be done is, go to the splunkd.log on the machines that are not forwarding logs (Located under $SPLUNK_HOME/var/log/ and do a tail -f splunkd.log) see any ERRORS and abnormal stuff? If yes, that would be the first step of your triage.&lt;/P&gt;

&lt;P&gt;For more accurate answers, please provide more information and ERRORS if any from your splunkd.log. Hope this helps!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 02:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264790#M79518</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2016-07-20T02:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: I have installed the Splunk forwarder, but why am I unable to search the event logs from all machines?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264791#M79519</link>
      <description>&lt;P&gt;Well written @Raghav2384&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 13:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-have-installed-the-Splunk-forwarder-but-why-am-I-unable-to/m-p/264791#M79519</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-20T13:52:52Z</dc:date>
    </item>
  </channel>
</rss>

