Splunk Enterprise

Why am I not getting logs from one source?

Ash1
Communicator

Hi all,

I have 2 servers  and each having 3 sources.

I am able to receive logs from 2 sources  from 2 servers but not receiving logs from one source

I checked there are logs on the server and no permission issues 

How to troubleshoot???

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the inputs are not disabled.

Use the splunk list monitor command to make sure the expected files are being monitored.

Check splunkd.log for messages relating to the files.

---
If this reply helps you, Karma would be appreciated.

Ash1
Communicator

i checked  disabled is 0
Use the splunk list monitor command --> for this i dont have access to universal forwarder to check 
i mentioned the source which was not coming in the search  with index=_internal source=splunkd  but i don't see any logs.



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is one old answer (you could found lot of those) https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-d... to solve this kind of issues.

r. Ismo

Ash1
Communicator

hi @isoutamo & @richgalloway , thank you for your inputs.
Actually the source was not added in inputs, i noticed it lately and added it, now i can see the logs.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...