Getting Data In

Missing New logs in Splunk

CONSORP
Loves-to-Learn Lots

I have NAS servers and splunk installed in Windows server, my new logs in a NAS server stopped indexing. I did troubleshooting and found bug in inputstatus.

Percent and file position in inputstatus shows 0.00 and 0 in splunk management port and i'm missing those logs in splunk

Inputstatus:
TailingProcessor: FileStatus in 8089 port

                                                   file position    0
                                                   file size        101010324                                    \\snx1_source_storagelogs-cpz_00000000.evtx
                                                   parent         \\snx1_source_storagelogs-cpz*.evtx
                                                   percent          0.00
                                                   type             finished reading

Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Back all the way up and start over. Tell us the whole story. Was it ever working OK? If so, what changed? What are your *.conf files that you used and what is in them? In particular, we need to see the inputs.conf and outputs.conf files on your forwarder. It is exceedingly unlikely that you found a bug in the forwarder and the output of splunk list monitor as well as splunk btool inputs list --debug.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Should be: splunk btool inputs list --debug

0 Karma

woodcock
Esteemed Legend

I always get that wrong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...