Monitoring Splunk

I am cloning _json sourcetype on managed splunk cloud to new custom name , the logs are not coming from log4j configuration

Nikhilsplunker
New Member

I have cloned a _json sourcetype to a custom sourcetype name and gave the correct URI for managed splunk cloud , still not being able to send logs to managed splunkcloud . I have also created a custom sourcetype cloning json_no_timestamp , it works, what are we missing
1) Is the issue on sourcetype definition or log4j configuration?
2) How to correct it ?

Tags (1)
0 Karma

Nikhilsplunker
New Member

Thanks will have a look and post back

0 Karma

woodcock
Esteemed Legend

We need more detail. In any case, check the error logs for splunkd and there is probably something there that you can fix.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...