Getting Data In

Log data of a particular sourcetype from one of the forwarder is missing in splunk

raj_mpl
Path Finder

Hi All,

In UF installed server ,we have monitor stanza to read the .log file from a particular source named it as one of the sourcetype.
I used to get the log feed upto 7 days . But suddenly it stopped and not able to see any log feed from that particular sourcetype only
But I am getting the different types of log files nearly from 8 sources from the same UF installed server to indexer

I had rebooted the UF but no luck . By running splunk btool command I can see the monitor stanza for the missing sourcetype in inputs.conf along with others

Please guide me on this
Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raj_mpl,
a little question: which day of the month was the stop day, the 1st?
in this case see the timestamp format because there's an error in time format interpratation: Splunk reads mm/dd/yyy, maybe you have dd/mm/yyy.
Bye.
Giuseppe

0 Karma

AnilPujar
Path Finder

other 8 sources also sending data to same indexes?

share inputs (from UF ) and indexes conf( from indexer)

0 Karma

raj_mpl
Path Finder

Yes , Other sources are also sending the data to same Index

[monitor:///user/sysem.log]
index=bal
sourcetype=mri

And for the same index different log from different sources are coming

0 Karma

vishaltaneja070
Motivator

@raj_mpl

check the _internal logs of forwarder to find out why the monitoring is suddenly stopperd. you will be able to see error message.

0 Karma

raj_mpl
Path Finder

What happens if we restart the splunk forwarder with a root user ?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...