Splunk Enterprise

Logs Stopped Forwarding to Index

heats
Explorer

Everytime I think I have Splunk figured out - I don't.

Logs stopped forwarding from my server to a specific index. I can see that logs are still forwarding probably to the default group but as you can see from my inputs.conf file it SHOULD be going to jim_test. I can confirm this is in the system/local so the precedence should be ok. Most of what I'm seeing in splunkd.log on the forwarder are successful calls "home".

[default]
host = ctl-ansible0104
queueSize = 10MB
sslVersions = tls

[monitor:///var/log/messages]
disabled = false
index = jim_test
sourcetype = linux_messages_syslog

Not sure what other things I should be troubleshooting.

Tags (1)
0 Karma
1 Solution

inventsekar
Super Champion

after adding /var/log/messages, did you restart the Splunk on UF?

the /var/log/messages file gets forwarded to wrong index or not getting forwarding at all?
are other log files are getting to splunk indexer properly?

PS ... If any post helped you in any way, pls give a hi-five to the author with an upvote. if your issue got resolved, please accept the reply as solution.. thanks.

View solution in original post

inventsekar
Super Champion

after adding /var/log/messages, did you restart the Splunk on UF?

the /var/log/messages file gets forwarded to wrong index or not getting forwarding at all?
are other log files are getting to splunk indexer properly?

PS ... If any post helped you in any way, pls give a hi-five to the author with an upvote. if your issue got resolved, please accept the reply as solution.. thanks.

heats
Explorer

Of course now it's working. Maybe I had my search syntax wrong 😞
I'm going to accept your answer since you took the time to reply to me.

0 Karma
Get Updates on the Splunk Community!

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...