Splunk Enterprise

Why am I not getting logs from one source?

Ash1
Communicator

Hi all,

I have 2 servers  and each having 3 sources.

I am able to receive logs from 2 sources  from 2 servers but not receiving logs from one source

I checked there are logs on the server and no permission issues 

How to troubleshoot???

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the inputs are not disabled.

Use the splunk list monitor command to make sure the expected files are being monitored.

Check splunkd.log for messages relating to the files.

---
If this reply helps you, Karma would be appreciated.

Ash1
Communicator

i checked  disabled is 0
Use the splunk list monitor command --> for this i dont have access to universal forwarder to check 
i mentioned the source which was not coming in the search  with index=_internal source=splunkd  but i don't see any logs.



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is one old answer (you could found lot of those) https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-a-universal-forwarder-lost-d... to solve this kind of issues.

r. Ismo

Ash1
Communicator

hi @isoutamo & @richgalloway , thank you for your inputs.
Actually the source was not added in inputs, i noticed it lately and added it, now i can see the logs.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...