Deployment Architecture

How to fix INFO TailingProcessor - Parsing configuration stanza issue? unable to see the data in Splunk

Hemnaath
Motivator

HI Team,

I am facing an issue with few of the servers which client had request to on-board new set of log data into splunk.  We had deployed the monitoring stanza & Parsing stanza by updating an existing app and app was successfully deployed into their respective servers. But we are unable to see the data ingest happening from the new monitoring stanza in Splunk. When troubleshooting could see this INFO related to the monitoring  stanza in _internal logs. Apart from this is INFO, there is no other messages or Events related to the below source found in the _internal logs.  

Monitoring Stanza details

[monitor:///usr/local/tet/t12/var/was/log/server.log]
sourcetype = usr:genericapp:server
index = test_index
disabled = 0
ignoreOlderThan = 14d

Parsing stanza:

[usr:genericapp:wfserver]

NO_BINARY_CHECK=true
LINE_BREAKER=([\r\n]+)\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\.\d{3}
TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD= 23
SHOULD_LINEMERGE=false

internal logs:

1:40:04.292 PM
02-25-2022 13:40:04.292 +0000 INFO TailingProcessor - Parsing configuration stanza: monitor:///usr/local/tet/t12/var/was/log/server.log

Kindly guide me to fix this .

 

Labels (2)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @Hemnaath,

The INFO log you are seeing doesn't seem to be a warning. Can you run the below command on the forwarder and check if the file has been monitored or not. 

$SPLUNK_HOME/bin/splunk list inputstatus

That can be considered as the first step to troubleshoot monitor inputs. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

Hemnaath
Motivator

Getting the below message when I run the command 

$SPLUNK_HOME/bin/splunk list inputstatus

This command [GET /services/admin/inputstatus] needs splunkd to be up, and splunkd is down.

Checked the splunk services are up and running. 

 

Tags (1)
0 Karma

blbr123
Explorer

Is the issue fixed?

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...