Getting Data In

How to troubleshoot not receiving data in a specific index from a specific host?

splunk_luis12
Path Finder

Hi folks,

I have a host that is sending different logs to Splunk, this host sends various logs successfully except for the syslog-ng logs.

Here you have an example of the inputs config (there are 3 inputs in this way not being received by Splunk)

[monitor:///store/data/log/cisco_ise]
disabled = false
host = xxxxxxxxxx
index = syslog
sourcetype = cisco:ise

  • Inputs appear when using the command 'splunk list monitor', then it doesn't seem a permissions issue.
  • Other logs are being successfully ingested by this host.
  • the syslog-ng is working as expected and it is receiving and storing logs on the hdd

Does anyone has an idea of steps I can follow to troubleshoot this?

Thanks in advance,

0 Karma

matt8679
Path Finder

I'm guessing its a permission issue with your syslog-ng directory. I would check that your user running splunk has the proper permissions to ingest the logs. I would compare the permissions of the files that work to the syslog-ng files.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the host is having problems reading certain logs or sending them to the indexers then there should be messages to that effect in splunkd.log.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...