Deployment Architecture

How to fix INFO TailingProcessor - Parsing configuration stanza issue (unable to see the data in Splunk)?

Hemnaath
Motivator

HI Team,

I am facing an issue with few of the servers which client had request to on-board new set of log data into splunk.  We had deployed the monitoring stanza & Parsing stanza by updating an existing app and app was successfully deployed into their respective servers. But we are unable to see the data ingest happening from the new monitoring stanza in Splunk. When troubleshooting could see this INFO related to the monitoring  stanza in _internal logs. Apart from this is INFO, there is no other messages or Events related to the below source found in the _internal logs.  

Monitoring Stanza details

[monitor:///usr/local/tet/t12/var/was/log/server.log]
sourcetype = usr:genericapp:server
index = test_index
disabled = 0
ignoreOlderThan = 14d

Parsing stanza:

[usr:genericapp:wfserver]

NO_BINARY_CHECK=true
LINE_BREAKER=([\r\n]+)\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\.\d{3}
TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD= 23
SHOULD_LINEMERGE=false

internal logs:

1:40:04.292 PM
02-25-2022 13:40:04.292 +0000 INFO TailingProcessor - Parsing configuration stanza: monitor:///usr/local/tet/t12/var/was/log/server.log

Kindly guide me to fix this .

 

Labels (2)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @Hemnaath,

The INFO log you are seeing doesn't seem to be a warning. Can you run the below command on the forwarder and check if the file has been monitored or not. 

$SPLUNK_HOME/bin/splunk list inputstatus

That can be considered as the first step to troubleshoot monitor inputs. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

Hemnaath
Motivator

Getting the below message when I run the command 

$SPLUNK_HOME/bin/splunk list inputstatus

This command [GET /services/admin/inputstatus] needs splunkd to be up, and splunkd is down.

Checked the splunk services are up and running. 

 

Tags (1)
0 Karma

Mohammed123
Loves-to-Learn Everything

same problem your issues is resolved with that or not,

Please provide steps to troubleshoot that problem

0 Karma

blbr123
Path Finder

Is the issue fixed?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...