Getting Data In

Log data of a particular sourcetype from one of the forwarder is missing in splunk

raj_mpl
Path Finder

Hi All,

In UF installed server ,we have monitor stanza to read the .log file from a particular source named it as one of the sourcetype.
I used to get the log feed upto 7 days . But suddenly it stopped and not able to see any log feed from that particular sourcetype only
But I am getting the different types of log files nearly from 8 sources from the same UF installed server to indexer

I had rebooted the UF but no luck . By running splunk btool command I can see the monitor stanza for the missing sourcetype in inputs.conf along with others

Please guide me on this
Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raj_mpl,
a little question: which day of the month was the stop day, the 1st?
in this case see the timestamp format because there's an error in time format interpratation: Splunk reads mm/dd/yyy, maybe you have dd/mm/yyy.
Bye.
Giuseppe

0 Karma

AnilPujar
Path Finder

other 8 sources also sending data to same indexes?

share inputs (from UF ) and indexes conf( from indexer)

0 Karma

raj_mpl
Path Finder

Yes , Other sources are also sending the data to same Index

[monitor:///user/sysem.log]
index=bal
sourcetype=mri

And for the same index different log from different sources are coming

0 Karma

vishaltaneja070
Motivator

@raj_mpl

check the _internal logs of forwarder to find out why the monitoring is suddenly stopperd. you will be able to see error message.

0 Karma

raj_mpl
Path Finder

What happens if we restart the splunk forwarder with a root user ?

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...