I'm trying to know why I can't feed data in splunk. I'm trying to get data from windows servers to splunk, I've created a UF on the Windows server that has the data that needs to be forwarded to splunk. I've configured inputs and outputs.conf files on the forwarder and have also configured inputs.com file on the indexer, all ports are opened, everything is set but I'm still not getting data in splunk. Any help?
Have you verified the forwarder can connect to the indexer?
Run this command to check if the forwarder is connected to the receiving instance.
"splunk list forward-server" , the indexer's ip should be in active state.
If its active , the next things to do is to check the splunkd.log of the universal forwarder.