Getting Data In

UF is not sending few logs

arunkns
New Member

Hi All,

I have UF installed in my windows machine and its has IIS logs and App logs. In last few days, my forwarder is not sending App logs to indexers. I have other machine which is having same log files, but that is sending logs to indexer. So, i have compared the permissions of files and folder, but i'm not seeing any difference between both systems. Can you please suggest me how to fix it.

Thanks,
Arunkumar

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
at first check if you're receiving logs fron that server
index=_internal host=your_server
If yes, there's an ingestion problem, otherwise there's a connection problem.

Ciao.
Giuseppe

0 Karma

arunkns
New Member

i'm able to see the host in _internal and the server has multiple logs like IIS and Apps. IIS logs are working fine, only apps logs are not coming into splunk

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi arunkns,
Could you share the input.conf stanza of app logs and a sample of your app logs?
Ciao.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for any Warning or Error message on UF which is not sending data ?

You can run $SPLUNK_HOME\bin\splunk.exe list inputstatus on UF & you can check which file/directory UF is monitoring.

0 Karma

arunkns
New Member

Thanks Harsmarvania57, I don't see any error in splunkd.log, but when I ran the command in windows (where UF is installed) and got below error.

AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!
error:00000000:lib(0):func(0):reason(0)
AES-GCM Decryption failed!
Decryption operation failed: AES-GCM Decryption failed!

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...