Getting Data In

How do I get my first log message?

netroworx
New Member

I have setup Universal forwarder on my Windows Server 2016 machine.

I have setup the Universal forwarder credentials to point to my Splunk Cloud.

By default shouldn't I now be getting data from the splunkd.log file?

Regards,

Greg

Tags (3)
0 Karma
1 Solution

skalliger
SplunkTrust
SplunkTrust

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

View solution in original post

0 Karma

skalliger
SplunkTrust
SplunkTrust

You can always check your metrics.log on your Universal Forwarder installation to check whether data is being sent. Otherwise, you can of course search for index=_internal and also specify host=xyz if you'd like to.

The other Spluk logs are also monitored, not only the splunkd.log. 🙂

0 Karma

netroworx
New Member

index=_internal shows a number of records.
Some of the records show a host of WIN2016 which is the machine I'm monitoring but when I search on host=WIN2016 I get no results.

0 Karma

netroworx
New Member

Data Summary shows: "Waiting for results..."

0 Karma

netroworx
New Member

If I search:
index=_internal host=WIN2016

I get results so I guess internal events are filtered out by default.

0 Karma

skalliger
SplunkTrust
SplunkTrust

Glad to hear you're receiving data. 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...