Getting Data In

I've setup a forwarder on Windows. My receiver is enabled and running tcpdump shows connection. However, Splunk is not indexing data.

bigfatyeastroll
Path Finder

one of my team has installed the forwarder on a Windows client. running tcpdump on the backend of splunk enterprise shows:

08:32:06.990056 IP xxx.56097 > splunk.xxx.9997: Flags [P.], seq 777:895, ack 1, win 512, length 118
08:32:06.990080 IP splunk.xxx.9997 >xxx.56097: Flags [.], ack 895, win 2512, length 0

my receiver is enabled on port 9997 but Splunk is not indexing the data. I have other clients using the same setup and they are being indexed.

Thoughts/Suggestions?

0 Karma
1 Solution

bigfatyeastroll
Path Finder

The forwarder was not setup using the Domain Admin and using the Domain\Username style. Thank!

View solution in original post

0 Karma

bigfatyeastroll
Path Finder

The forwarder was not setup using the Domain Admin and using the Domain\Username style. Thank!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarder has inputs enabled and that those inputs reference indexes that exist.

---
If this reply helps you, Karma would be appreciated.
0 Karma

bigfatyeastroll
Path Finder

Could it be something in the setup during the installation of the Forwarder?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...