Splunk Enterprise

Why am I not getting logs from one source?

Ash1
Communicator

Hi all,

I have 2 servers  and each having 3 sources.

I am able to receive logs from 2 sources  from 2 servers but not receiving logs from one source

I checked there are logs on the server and no permission issues 

How to troubleshoot???

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the inputs are not disabled.

Use the splunk list monitor command to make sure the expected files are being monitored.

Check splunkd.log for messages relating to the files.

---
If this reply helps you, Karma would be appreciated.

Ash1
Communicator

i checked  disabled is 0
Use the splunk list monitor command --> for this i dont have access to universal forwarder to check 
i mentioned the source which was not coming in the search  with index=_internal source=splunkd  but i don't see any logs.



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is one old answer (you could found lot of those) https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-d... to solve this kind of issues.

r. Ismo

Ash1
Communicator

hi @isoutamo & @richgalloway , thank you for your inputs.
Actually the source was not added in inputs, i noticed it lately and added it, now i can see the logs.

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...