Getting Data In

Missing New logs in Splunk

CONSORP
Loves-to-Learn Lots

I have NAS servers and splunk installed in Windows server, my new logs in a NAS server stopped indexing. I did troubleshooting and found bug in inputstatus.

Percent and file position in inputstatus shows 0.00 and 0 in splunk management port and i'm missing those logs in splunk

Inputstatus:
TailingProcessor: FileStatus in 8089 port

                                                   file position    0
                                                   file size        101010324                                    \\snx1_source_storagelogs-cpz_00000000.evtx
                                                   parent         \\snx1_source_storagelogs-cpz*.evtx
                                                   percent          0.00
                                                   type             finished reading

Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Back all the way up and start over. Tell us the whole story. Was it ever working OK? If so, what changed? What are your *.conf files that you used and what is in them? In particular, we need to see the inputs.conf and outputs.conf files on your forwarder. It is exceedingly unlikely that you found a bug in the forwarder and the output of splunk list monitor as well as splunk btool inputs list --debug.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Should be: splunk btool inputs list --debug

0 Karma

woodcock
Esteemed Legend

I always get that wrong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...