Getting Data In

Missing New logs in Splunk

CONSORP
Loves-to-Learn Lots

I have NAS servers and splunk installed in Windows server, my new logs in a NAS server stopped indexing. I did troubleshooting and found bug in inputstatus.

Percent and file position in inputstatus shows 0.00 and 0 in splunk management port and i'm missing those logs in splunk

Inputstatus:
TailingProcessor: FileStatus in 8089 port

                                                   file position    0
                                                   file size        101010324                                    \\snx1_source_storagelogs-cpz_00000000.evtx
                                                   parent         \\snx1_source_storagelogs-cpz*.evtx
                                                   percent          0.00
                                                   type             finished reading

Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Back all the way up and start over. Tell us the whole story. Was it ever working OK? If so, what changed? What are your *.conf files that you used and what is in them? In particular, we need to see the inputs.conf and outputs.conf files on your forwarder. It is exceedingly unlikely that you found a bug in the forwarder and the output of splunk list monitor as well as splunk btool inputs list --debug.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Should be: splunk btool inputs list --debug

0 Karma

woodcock
Esteemed Legend

I always get that wrong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...