Deployment Architecture

Splunk Forwarder No Longer passing file to enterprise system

999chris
New Member

Hi All,

I'm muddling through Splunk as I go. I'm part of a team working with it but we're all having to feel our way through a little bit blind, but we have made some progress none the less as after a little while it starts to make sense.

However I was playing with the Data Inputs and Source Types on Splunk web and now the forwarder is not passing a log file through.

I cannot determine why, I managed to track down the splunkd log on the forwarder box and it says

TailingProcessor - Parsing configuration stanza: monitor://\mypath\mylog.log

Then no other mention of such file. The file has changed since it was last indexed so I don't know whats going on. Any help is greatly appreciated.

0 Karma

ddrillic
Ultra Champion

It's good to run ./splunk cmd btool inputs list monitor on the forwarder to ensure that the proper file is being monitored.

The following is great - I can't find my data!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...