Getting Data In

Can't feed data into Splunk

essibong1
New Member

I'm trying to know why I can't feed data in splunk. I'm trying to get data from windows servers to splunk, I've created a UF on the Windows server that has the data that needs to be forwarded to splunk. I've configured inputs and outputs.conf files on the forwarder and have also configured inputs.com file on the indexer, all ports are opened, everything is set but I'm still not getting data in splunk. Any help?

Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you verified the forwarder can connect to the indexer?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mloyola_splunk
Splunk Employee
Splunk Employee

Run this command to check if the forwarder is connected to the receiving instance.
"splunk list forward-server" , the indexer's ip should be in active state.

If its active , the next things to do is to check the splunkd.log of the universal forwarder.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...