Getting Data In

Ubuntu 12.04 , rsyslog and splunk storm

pepepito
New Member

Hi.

I just setup a free account in splunkstorm and try to set up rsyslog base on the documentation and I didn't see any data but strangely enough my 1G free is full but I don't see any data and even if I search nothing shows up.

I get tons of this messages on the GUI :

Reached end-of-stream while waiting for more data from peer mt-indexer-i-f49bed87.prod-root. Search results might be incomplete!

my rsyslog file was :

$ModLoad imuxsock # provides support for local system logging
$ModLoad imklog # provides kernel logging support (previously done by rklogd)
$ModLoad imfile # provides --MARK-- message capability

$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

$RepeatedMsgReduction on

$FileOwner syslog
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
$PrivDropToUser syslog
$PrivDropToGroup syslog

$WorkDirectory /var/spool/rsyslog

$InputFileName /var/log/drupal.log
$InputFileTag drupal:
$InputFileStateFile stat-drupal
$InputFileSeverity info
$InputRunFileMonitor
$InputFilePollingInterval 10

. @@logs4.splunkstorm.com:20244
$IncludeConfig /etc/rsyslog.d/*.conf

In inputs network data page it says "Data last received" "N/A" but the storage is full, I don't get it.

can someone help me to figure out this ?

Thanks.

P.S : my timezone is setup to UTC 0000 on the server and splunkstorm

Tags (1)
0 Karma

Ed
Splunk Employee
Splunk Employee

Hi pepepito,

We had some issues with a searchhead yesterday. They should be resolved and you should be able to see your data now. If not, please file a Storm support ticket and we'll look into it!

Thanks,
Ed

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...