Universal forwarder sending data _internal logs and we are receiving those logs and appeared on search heads.
But we deployed an add-on on the same universal forwarder. But we are not receiving data from the index which is present in the add-on. We created index on indexers.we are receiving data to this index from other UF's.
After deploying add-on we restarted UF
Example: index=_internal host=abc (we are getting splunkd logs)
index= test1 host=abc (we are not able see any logs)
can any one explain why this happens??
Which addon did you deploy? Does this addon set the host
value based on the event payload? Did you enable the inputs?
You may want to start by including your inputs.conf from the forwarder to enable additional help.
Dont you see any clue from Indexer and UF _internal logs.Just search for this indexname as keyword.
Obviously something is not configured properly for your non-internal data monitoring. I would suggest going through this post for troubleshooting steps.
http://docs.splunk.com/Documentation/Splunk/7.0.1/Troubleshooting/Cantfinddata
we have checked diag file from universal forwarder everything configured properly