Getting Data In

How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

vad34
Path Finder

Hello guys,

I have new Splunk 6.3.1 installation on Centos 6.7.
After installation, there are no events coming to Splunk. I reinstalled Splunk, but still no data..
I configured data inputs and the index, but with no luck.
Another installation with Splunk 6.2.3 on Linux CentOS 6.6 works fine.

Any ideas?
Tnx in advance

0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

Using the Splunk admin account, verify first that you see data being ingested on the indexer e.g. splunkd.log from the indexer.

index=_internal source=*splunkd.log

If you are getting data here the indexer is ingesting data from its own local monitors. Since it is new install next check to ensure you have configured a receiving port. So other Splunk instances can send data to the indexer.

0 Karma

vad34
Path Finder

Tnx for the reply, yes the data indexed on internal source and i am able to see local linux logs.
When it comes to Win & Linux remote machine i got NO data events.
I installed splunk 6.2.3 instead splunk 6.3.1 but still the same issue (

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...