Hi Team,
We can see that data has been picked up by heavy forwarder and its communicating fine with the indexer - Checked in splunkd log of heavy forwarder. But we are not able to find that data in indexer - How can we check whether that data has been forwarded by heavy forwarder to the indexer - Any logs or command to run to check the functionality.
Thanks | Ravi
Have you checked this?
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata
/K