Getting Data In

Log data of a particular sourcetype from one of the forwarder is missing in splunk

raj_mpl
Path Finder

Hi All,

In UF installed server ,we have monitor stanza to read the .log file from a particular source named it as one of the sourcetype.
I used to get the log feed upto 7 days . But suddenly it stopped and not able to see any log feed from that particular sourcetype only
But I am getting the different types of log files nearly from 8 sources from the same UF installed server to indexer

I had rebooted the UF but no luck . By running splunk btool command I can see the monitor stanza for the missing sourcetype in inputs.conf along with others

Please guide me on this
Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raj_mpl,
a little question: which day of the month was the stop day, the 1st?
in this case see the timestamp format because there's an error in time format interpratation: Splunk reads mm/dd/yyy, maybe you have dd/mm/yyy.
Bye.
Giuseppe

0 Karma

AnilPujar
Path Finder

other 8 sources also sending data to same indexes?

share inputs (from UF ) and indexes conf( from indexer)

0 Karma

raj_mpl
Path Finder

Yes , Other sources are also sending the data to same Index

[monitor:///user/sysem.log]
index=bal
sourcetype=mri

And for the same index different log from different sources are coming

0 Karma

vishaltaneja070
Motivator

@raj_mpl

check the _internal logs of forwarder to find out why the monitoring is suddenly stopperd. you will be able to see error message.

0 Karma

raj_mpl
Path Finder

What happens if we restart the splunk forwarder with a root user ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...