Collector troubleshooting
Hi, I installed collector on a new host I am trying to add to sumologic; and I am able to see it under manage>collector. However, when I start simple search (_collector=) I am unable to see any logs. I currently trying to access /var/log/messages and I can see it listed in manage>collector. I restarted collector on the host and I can confirm it is running. What would be right way of troubleshooting this?
-
Igor, Were you able to get data? Sometimes the issue can be related to timestamp, for example your logs have a timestamp format that Sumo doesn't recognize.To see if this is the issue, you can run the search using the "Use Receipt Time" and choose a timeframe that includes the time when you ingested your data.If this was your issue, you can tell Sumo how to correctly recognize the format of your timestamp:http://help.sumologic.com/Send_Data/Sources/04Reference_Information_for_Sources/Timestamps%2C_Time_Zones%2C_Time_Ranges%2C_and_Date_FormatsCheers,Mario
Please sign in to leave a comment.
Comments
2 comments