Getting Data In

Why is my forwarder not forwarding data other than _internal?

sathiyasun
Explorer

I have forwarder not forwarding any input data other than _internal.

Checks performed:
splunk version - 6.4.2
Forwarder is up and running.
Checked the $SPLUNK_HOME/etc/system/local/inputs.conf . -- Checked the host name
Checked the $SPLUNK_HOME/etc/system/local/deploymentclient.conf
Checked the $SPLUNK_HOME/etc/system/local/server.conf
I don't see any error/warning in splunkd.log.
File path for the log files.

I have restarted the forwarder several times but no luck.
The inputs in the /etc/app are not forwarding.

Please advise.

0 Karma

pradeepkumarg
Influencer

Does the log files have data in them to forward?
Cross check the path for any type-o ?

0 Karma

sathiyasun
Explorer

Fixed, There was an mistake in the inputs whitelist. It works now. Thanks.

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...