Splunk Enterprise

Splunk app for Logbinder - Event Entries empty

juerchri
New Member

Hi guys,

I installed Supercharger, Splunk and Splunk app for Logbinder in order to configure log forwarders and have them visualized within Splunk (like here https://support.logbinder.com/SuperchargerKB/50135/8-Install-Supercharger-with-Splunk-Light-and-the-...)
So far everything worked flawless, Events are forwarded and collected but when looking at the event entries in Splunk they are not showing any data:

alt text

When looking inside the forwarded Events everything looks as it should, only what is displayed in Splunk is wrong.
Help really appreciated!

Thanks and Regards

One additional question: The forwarded events are stored in a event file. Are they also stored within the SQL DB which Logbinder creates? Only relying on this file seems a bit crazy to me? How is Splunk crawling this file?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...