Getting Data In

Why is my forwarder not forwarding data other than _internal?

sathiyasun
Explorer

I have forwarder not forwarding any input data other than _internal.

Checks performed:
splunk version - 6.4.2
Forwarder is up and running.
Checked the $SPLUNK_HOME/etc/system/local/inputs.conf . -- Checked the host name
Checked the $SPLUNK_HOME/etc/system/local/deploymentclient.conf
Checked the $SPLUNK_HOME/etc/system/local/server.conf
I don't see any error/warning in splunkd.log.
File path for the log files.

I have restarted the forwarder several times but no luck.
The inputs in the /etc/app are not forwarding.

Please advise.

0 Karma

pradeepkumarg
Influencer

Does the log files have data in them to forward?
Cross check the path for any type-o ?

0 Karma

sathiyasun
Explorer

Fixed, There was an mistake in the inputs whitelist. It works now. Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...