Getting Data In

UF is not sending few logs

arunkns
New Member

Hi All,

I have UF installed in my windows machine and its has IIS logs and App logs. In last few days, my forwarder is not sending App logs to indexers. I have other machine which is having same log files, but that is sending logs to indexer. So, i have compared the permissions of files and folder, but i'm not seeing any difference between both systems. Can you please suggest me how to fix it.

Thanks,
Arunkumar

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
at first check if you're receiving logs fron that server
index=_internal host=your_server
If yes, there's an ingestion problem, otherwise there's a connection problem.

Ciao.
Giuseppe

0 Karma

arunkns
New Member

i'm able to see the host in _internal and the server has multiple logs like IIS and Apps. IIS logs are working fine, only apps logs are not coming into splunk

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
Could you share the input.conf stanza of app logs and a sample of your app logs?
Ciao.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for any Warning or Error message on UF which is not sending data ?

You can run $SPLUNK_HOME\bin\splunk.exe list inputstatus on UF & you can check which file/directory UF is monitoring.

0 Karma

arunkns
New Member

Thanks Harsmarvania57, I don't see any error in splunkd.log, but when I ran the command in windows (where UF is installed) and got below error.

AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...