<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I check whether the data is being forwarded to indexer in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471906#M24354</link>
    <description>&lt;P&gt;Search for the data.  Look for it in the index specified in the inputs.conf file as well as in your Last Chance index ("main" or whatever you've designated), if you have one.&lt;/P&gt;

&lt;P&gt;Another way is to look in the internal logs.  Search &lt;CODE&gt;index=_internal source=*metrics.log group=per_source_thruput&lt;/CODE&gt; and look for &lt;CODE&gt;series&lt;/CODE&gt; field values that match your source names.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Dec 2019 14:17:27 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-12-23T14:17:27Z</dc:date>
    <item>
      <title>How can I check whether the data is being forwarded to indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471905#M24353</link>
      <description>&lt;P&gt;How can I check whether the data from a server is being forwarded to indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 09:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471905#M24353</guid>
      <dc:creator>pratapa</dc:creator>
      <dc:date>2019-12-23T09:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I check whether the data is being forwarded to indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471906#M24354</link>
      <description>&lt;P&gt;Search for the data.  Look for it in the index specified in the inputs.conf file as well as in your Last Chance index ("main" or whatever you've designated), if you have one.&lt;/P&gt;

&lt;P&gt;Another way is to look in the internal logs.  Search &lt;CODE&gt;index=_internal source=*metrics.log group=per_source_thruput&lt;/CODE&gt; and look for &lt;CODE&gt;series&lt;/CODE&gt; field values that match your source names.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 14:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471906#M24354</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-23T14:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I check whether the data is being forwarded to indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471907#M24355</link>
      <description>&lt;P&gt;I am checking with the following  search query whether the data is being forwarded to indexer from  host1.  But search query returned &lt;BR /&gt;
No results found.&lt;/P&gt;

&lt;P&gt;index=_internal source=*metrics.log group=per_source_thruput host=host1&lt;/P&gt;

&lt;P&gt;How should I troubleshoot from here.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471907#M24355</guid>
      <dc:creator>pratapa</dc:creator>
      <dc:date>2020-09-30T03:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I check whether the data is being forwarded to indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471908#M24356</link>
      <description>&lt;P&gt;Look in the internal index for tcpin_connection events from host1.  &lt;CODE&gt;index=_internal source=*splunkd.log host=host1 tcpin_connection&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;If you find nothing there then data is not being forwarded.  Check the forwarder's splunkd.log ($SPLUNK_HOME/var/log/splunk/splunkd.log) for possible reasons.  Check your firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-I-check-whether-the-data-is-being-forwarded-to-indexer/m-p/471908#M24356</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-30T03:29:55Z</dc:date>
    </item>
  </channel>
</rss>

