zcat syslog.*.gz | grep clamav
i compare a successful one with the one who missing log in splunk,
both have clamav summary log in syslog
https://drive.google.com/file/d/0Bxs_ao6uuBDUc3hoOHVoVW5pM2c/view?usp=sharing
https://drive.google.com/file/d/0Bxs_ao6uuBDUZ2tYdzhydHNpVms/view?usp=sharing
Hi cyberportnoc,
check using a larger time period, often the problem is in differences in timestamp.
Bye.
Giuseppe
Hi cyberportnoc,
check using a larger time period, often the problem is in differences in timestamp.
Bye.
Giuseppe
i found the reason in the recorded video case,
because the host use the same host name as another host, icnetwork01
so the file actually is icnetwork01 which exist in the list
after troubleshooting , i found the reasons that no log in these hosts,
some reasons that log file are locked by another process
,and some are misconfiguration of rsyslog.conf
i am Martin and sent to support@splunk.com, but i do not know ssh's password of splunk,
i can only have admin right to access web, so far at night shift. is there any one needed webex to investigate this issue?
Hi Martin,
surely you need SSH access to splunk servers, aniway they'll contact you.
Bye.
Giuseppe
i had used 7 days, still no log
these log generated every day
Hi cyberportnoc,
Temporarly send your syslogs to a test index for a little period and search on this index, in this way you can be sure that you're receiving logs.
If there aren't there's a different problem to debug.
Bye.
Giuseppe
https://drive.google.com/file/d/0Bxs_ao6uuBDUVVBJcTczdlcwNUk/view?usp=sharing
use 30 days, still no log