Getting Data In

How to see Events coming into the Indexer?

pfabrizi
Path Finder

I am forwarding events from windows events from Graylog to a load balance point in front of a UF using a TCP input then forwarding to my indexers. I can see in the metrics.log on the UF that data is coming in and I can see on the indexer data coming in from the IP of of my UF. When I search i am not seeing that sourcetype.

Where can I look to see what might be happening on the indexer?

Thanks!

0 Karma

horsefez
Motivator

@pfabrizi,

how does the inputs.conf on your UF and on your indexer look like?

Please post the contents of those files.

0 Karma

pfabrizi
Path Finder

what ever the issue was it is resolved. I think they are throttling the graylog events and I just didn't wait long enough.

Thanks!

0 Karma

somesoni2
Revered Legend

An amazing read is this Splunk doc page for these type of troubleshooting:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Cantfinddata

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...