Hi,
We have a setup in a remote machine that receives data from database in form of excel sheets and forwards it to Splunk environment
with the help of a universal forwarder.
But when i am searching that particular data it is not coming in splunk. Any idea why this is happening even if the .conf files are fine?
There are a ton of reasons.
Is splunk running?
Is inputs.conf configured to send anything?
Is outputs.conf configured to show where to send it?
Does the forwarder have a route to the indexer hosts?
Do the firewalls and other network equipment allow connections from the UF to the indexers (port 9997 or maybe 9998 or ???)?
Is _time correct for your events (maybe being thrown into the future)?
Are you indexers setup to receive anything?
Are you monitoring file on UF? Following are good source to debug
https://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs
https://answers.splunk.com/answers/177588/how-to-debug-why-a-universal-forwarder-is-reading.html