Getting Data In

Splunk logs are not generating , we troubleshooted by restarting the services by doing basic troubleshoot but still logs are not getting in


Hi team ,

splunk logs are not getting in , we done basic troubleshoot but still logs are not getting generated

[splunk@heavyforwarder3 sourcefire]$ cd log
[splunk@heavyforwarder3 log]$ ls -ltr
total 0

we have the confiugration file for estreamer.conf set as

disabled = 0
source = eStreamer
sourcetype = sourcefire:network:client_check
index = intrusion
interval = 60

disabled = 0
source = eStreamer
sourcetype = sourcefire:network:ids
index = intrusion
crcSalt =

when i had tried running
index="_internal" host="heavyforwarder3" "sourcefire" , we got this excepotion
02-02-2018 05:35:36.074 -0500 INFO ExecProcessor - New scheduled exec process: python /opt/splunk/etc/apps/sourcefire/bin/

how can we troubleshoot more on this.

0 Karma


From the inputs.conf doc, it says that when using a script, the script must be located in a specific directory, which doesn't appear to be the case in your setup:

* The <cmd> must reside in one of the following directories:
  * $SPLUNK_HOME/etc/system/bin/
  * $SPLUNK_HOME/etc/apps/$YOUR_APP/bin/
  * $SPLUNK_HOME/bin/scripts/

The monitor statement should use the full absolute path, not the $SPLUNK_HOME variable within it, again from the docs:

* You must specify the input type and then the path, so put three slashes in
  your path if you are starting at the root on *nix systems (to include the
  slash that indicates an absolute path).

Try changings these to follow the spec and then see what you get after.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...