Getting Data In

Log data of a particular sourcetype from one of the forwarder is missing in splunk

raj_mpl
Path Finder

Hi All,

In UF installed server ,we have monitor stanza to read the .log file from a particular source named it as one of the sourcetype.
I used to get the log feed upto 7 days . But suddenly it stopped and not able to see any log feed from that particular sourcetype only
But I am getting the different types of log files nearly from 8 sources from the same UF installed server to indexer

I had rebooted the UF but no luck . By running splunk btool command I can see the monitor stanza for the missing sourcetype in inputs.conf along with others

Please guide me on this
Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raj_mpl,
a little question: which day of the month was the stop day, the 1st?
in this case see the timestamp format because there's an error in time format interpratation: Splunk reads mm/dd/yyy, maybe you have dd/mm/yyy.
Bye.
Giuseppe

0 Karma

AnilPujar
Path Finder

other 8 sources also sending data to same indexes?

share inputs (from UF ) and indexes conf( from indexer)

0 Karma

raj_mpl
Path Finder

Yes , Other sources are also sending the data to same Index

[monitor:///user/sysem.log]
index=bal
sourcetype=mri

And for the same index different log from different sources are coming

0 Karma

vishaltaneja070
Motivator

@raj_mpl

check the _internal logs of forwarder to find out why the monitoring is suddenly stopperd. you will be able to see error message.

0 Karma

raj_mpl
Path Finder

What happens if we restart the splunk forwarder with a root user ?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...