Deployment Architecture

Splunk Forwarder No Longer passing file to enterprise system

999chris
New Member

Hi All,

I'm muddling through Splunk as I go. I'm part of a team working with it but we're all having to feel our way through a little bit blind, but we have made some progress none the less as after a little while it starts to make sense.

However I was playing with the Data Inputs and Source Types on Splunk web and now the forwarder is not passing a log file through.

I cannot determine why, I managed to track down the splunkd log on the forwarder box and it says

TailingProcessor - Parsing configuration stanza: monitor://\mypath\mylog.log

Then no other mention of such file. The file has changed since it was last indexed so I don't know whats going on. Any help is greatly appreciated.

0 Karma

ddrillic
Ultra Champion

It's good to run ./splunk cmd btool inputs list monitor on the forwarder to ensure that the proper file is being monitored.

The following is great - I can't find my data!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...