Deployment Architecture

Splunk Forwarder No Longer passing file to enterprise system

999chris
New Member

Hi All,

I'm muddling through Splunk as I go. I'm part of a team working with it but we're all having to feel our way through a little bit blind, but we have made some progress none the less as after a little while it starts to make sense.

However I was playing with the Data Inputs and Source Types on Splunk web and now the forwarder is not passing a log file through.

I cannot determine why, I managed to track down the splunkd log on the forwarder box and it says

TailingProcessor - Parsing configuration stanza: monitor://\mypath\mylog.log

Then no other mention of such file. The file has changed since it was last indexed so I don't know whats going on. Any help is greatly appreciated.

0 Karma

ddrillic
Ultra Champion

It's good to run ./splunk cmd btool inputs list monitor on the forwarder to ensure that the proper file is being monitored.

The following is great - I can't find my data!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...