Splunk Enterprise

Why am I not getting logs from one source?

Ash1
Communicator

Hi all,

I have 2 servers  and each having 3 sources.

I am able to receive logs from 2 sources  from 2 servers but not receiving logs from one source

I checked there are logs on the server and no permission issues 

How to troubleshoot???

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the inputs are not disabled.

Use the splunk list monitor command to make sure the expected files are being monitored.

Check splunkd.log for messages relating to the files.

---
If this reply helps you, Karma would be appreciated.

Ash1
Communicator

i checked  disabled is 0
Use the splunk list monitor command --> for this i dont have access to universal forwarder to check 
i mentioned the source which was not coming in the search  with index=_internal source=splunkd  but i don't see any logs.



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is one old answer (you could found lot of those) https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-d... to solve this kind of issues.

r. Ismo

Ash1
Communicator

hi @isoutamo & @richgalloway , thank you for your inputs.
Actually the source was not added in inputs, i noticed it lately and added it, now i can see the logs.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...