Getting Data In

Splunk is not logging data

pratapa
Explorer

User complained that Splunk is not logging data

Data being stopped logging after 1:40 PM on Tue Dec 3rd.

Please help me in resolving the problem.

alt text

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pratapa,
there could be many reasons because your Splunk doesn't receive data, you should debug point by point all your architecture:

  • in the last day, there was any change in configuration (roles, grants, deployed TAs)?
  • another user (e.g. admin) can see all the data?
  • is there any block in firewall routes between Universal Forwarder and Splunk Server?
  • from that server, you're continuing to receive in the same period Splunk internal logs (index=_internal host=your_host)?
  • the target server created the new logs?

Then check the inputs.conf deployed to that server.

Ciao.
Giuseppe

0 Karma

kartm2020
Communicator

Hi Pratapa,
Can you please provide the type of logs ?
Is it stopped from all the sources or Host or Sourcetype ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We have to know more about your Splunk environment to offer specific help, but there are some things you can check.
Are the forwarders still running?
Is the data source still producing events?
If the data comes from a monitored file, is the file still present and has permissions allowing Splunk to read it?
Did any network changes happen that might prevent the data from getting to the indexer(s)?
Are there any errors in splunkd.log that might indicate a problem getting data in?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...