Deployment Architecture

How to fix INFO TailingProcessor - Parsing configuration stanza issue (unable to see the data in Splunk)?

Hemnaath
Motivator

HI Team,

I am facing an issue with few of the servers which client had request to on-board new set of log data into splunk.  We had deployed the monitoring stanza & Parsing stanza by updating an existing app and app was successfully deployed into their respective servers. But we are unable to see the data ingest happening from the new monitoring stanza in Splunk. When troubleshooting could see this INFO related to the monitoring  stanza in _internal logs. Apart from this is INFO, there is no other messages or Events related to the below source found in the _internal logs.  

Monitoring Stanza details

[monitor:///usr/local/tet/t12/var/was/log/server.log]
sourcetype = usr:genericapp:server
index = test_index
disabled = 0
ignoreOlderThan = 14d

Parsing stanza:

[usr:genericapp:wfserver]

NO_BINARY_CHECK=true
LINE_BREAKER=([\r\n]+)\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\.\d{3}
TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD= 23
SHOULD_LINEMERGE=false

internal logs:

1:40:04.292 PM
02-25-2022 13:40:04.292 +0000 INFO TailingProcessor - Parsing configuration stanza: monitor:///usr/local/tet/t12/var/was/log/server.log

Kindly guide me to fix this .

 

Labels (2)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @Hemnaath,

The INFO log you are seeing doesn't seem to be a warning. Can you run the below command on the forwarder and check if the file has been monitored or not. 

$SPLUNK_HOME/bin/splunk list inputstatus

That can be considered as the first step to troubleshoot monitor inputs. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

Hemnaath
Motivator

Getting the below message when I run the command 

$SPLUNK_HOME/bin/splunk list inputstatus

This command [GET /services/admin/inputstatus] needs splunkd to be up, and splunkd is down.

Checked the splunk services are up and running. 

 

Tags (1)
0 Karma

Mohammed123
Loves-to-Learn Everything

same problem your issues is resolved with that or not,

Please provide steps to troubleshoot that problem

0 Karma

blbr123
Path Finder

Is the issue fixed?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...