<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data from forwarder arrives at the indexer but does not get indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9965#M234</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for any data from that forwarder in splunk.&lt;/P&gt;

&lt;P&gt;This is what I see in the metrics.log on the indexer:
03-03-2010 17:55:25.602 INFO  Metrics - group=tcpin_connections, :61464:9997, connectionType=cooked, sourcePort=61464, sourceHost=, sourceIp=, destPort=9997, _tcp_Bps=6.39, _tcp_KBps=0.01, _tcp_avg_thruput=13.09, _tcp_Kprocessed=8166.00, _tcp_eps=0.03&lt;/P&gt;

&lt;P&gt;Is there a way to find out where the data went that arrived on the indexer?&lt;/P&gt;</description>
    <pubDate>Thu, 04 Mar 2010 01:25:08 GMT</pubDate>
    <dc:creator>chris</dc:creator>
    <dc:date>2010-03-04T01:25:08Z</dc:date>
    <item>
      <title>Data from forwarder arrives at the indexer but does not get indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9965#M234</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for any data from that forwarder in splunk.&lt;/P&gt;

&lt;P&gt;This is what I see in the metrics.log on the indexer:
03-03-2010 17:55:25.602 INFO  Metrics - group=tcpin_connections, :61464:9997, connectionType=cooked, sourcePort=61464, sourceHost=, sourceIp=, destPort=9997, _tcp_Bps=6.39, _tcp_KBps=0.01, _tcp_avg_thruput=13.09, _tcp_Kprocessed=8166.00, _tcp_eps=0.03&lt;/P&gt;

&lt;P&gt;Is there a way to find out where the data went that arrived on the indexer?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2010 01:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9965#M234</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2010-03-04T01:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Data from forwarder arrives at the indexer but does not get indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9966#M235</link>
      <description>&lt;P&gt;Chances are you have the forwarder inputs set to use an index that doesn't exist on the indexer.  Check your inputs.conf file and see what "index =".  Add that index to the indexer and your data should show up.  &lt;/P&gt;

&lt;P&gt;DJ &lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2010 03:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9966#M235</guid>
      <dc:creator>dskillman</dc:creator>
      <dc:date>2010-03-04T03:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data from forwarder arrives at the indexer but does not get indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9967#M236</link>
      <description>&lt;P&gt;The index did exist on the indexer, I reinstalled the agent among other things. I can't say what was wrong in the end. This is a list of things I check to get forwarders running: Splunk user must have read access to the files that will be monitored, Correct server configured in outputs.conf, "INFO TcpInputProc - Connection accepted from" Messages in splunkd.log on the indexer, Check for Messages in metrics.log on the indexer, Query splunk for events you expect&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2010 22:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-forwarder-arrives-at-the-indexer-but-does-not-get/m-p/9967#M236</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2010-03-05T22:50:42Z</dc:date>
    </item>
  </channel>
</rss>

