Hi, I am currently facing an issue where my Splunk Universal Forwarder is able to establish connection with the Splunk Server but it is unable to port over the data from the target folder of interest. Is there a way to trouble shoot this? A diagnostic test of index="_internal" would show that Splunk is streaming in system logs from my PC, thus proving that a link has already been established with the Splunk Server. However, trying to query using index="ForwarderText_index" (my target index for the targeted files), would yield nothing. Splunk Universal Forwarder Installation Configuration Details: Server: MyServerName Port/Management Port: 8089 (default) Target Folder: C:\Users\MyUserName\Documents\MyProject\logs\Splunk_Monitoring_Folder _______________________________________ inputs.conf location: C:\Program Files\SplunkUniversalForwarder\etc\system\local File contents: [monitor://C:\Users\cftfda01\Documents\MyProject\logs\Splunk_Monitoring_Folder\SubFolder01] disabled = false index = ForwarderText_index host = MyComputerID _______________________________________ outputs.conf location: C:\Program Files\SplunkUniversalForwarder\etc\system\local [tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] server =MyServerName:9997 [tcpout-server://MyServerName:9997]
... View more