Getting Data In

UF is not sending few logs

arunkns
New Member

Hi All,

I have UF installed in my windows machine and its has IIS logs and App logs. In last few days, my forwarder is not sending App logs to indexers. I have other machine which is having same log files, but that is sending logs to indexer. So, i have compared the permissions of files and folder, but i'm not seeing any difference between both systems. Can you please suggest me how to fix it.

Thanks,
Arunkumar

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
at first check if you're receiving logs fron that server
index=_internal host=your_server
If yes, there's an ingestion problem, otherwise there's a connection problem.

Ciao.
Giuseppe

0 Karma

arunkns
New Member

i'm able to see the host in _internal and the server has multiple logs like IIS and Apps. IIS logs are working fine, only apps logs are not coming into splunk

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
Could you share the input.conf stanza of app logs and a sample of your app logs?
Ciao.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for any Warning or Error message on UF which is not sending data ?

You can run $SPLUNK_HOME\bin\splunk.exe list inputstatus on UF & you can check which file/directory UF is monitoring.

0 Karma

arunkns
New Member

Thanks Harsmarvania57, I don't see any error in splunkd.log, but when I ran the command in windows (where UF is installed) and got below error.

AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...