<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to see the forwarder but data is being received? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291397#M55541</link>
    <description>&lt;P&gt;You are right Adonio, when I run this query I get this result.&lt;/P&gt;

&lt;P&gt;What I meant the "Search" page which shows all Hosts added,...and the moment I have the message "No data has been added",,,,whereas I should have the hostname on my cisco device.&lt;/P&gt;

&lt;P&gt;Any idea ?&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2017 20:42:19 GMT</pubDate>
    <dc:creator>Lenval06</dc:creator>
    <dc:date>2017-05-12T20:42:19Z</dc:date>
    <item>
      <title>Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291395#M55539</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I setup a forwarder on a linux server and setup Splunk to listen on port 9997 and I added the index name (cisco) I previously setup into the inputs.conf file.&lt;BR /&gt;
On the Splunk indexer, if I search "index=cisco", I can see all my data.&lt;/P&gt;

&lt;P&gt;However, my "Search" page is not displaying any "Hosts", any "Sources" and any "SourceTypes"....whereas I am receiving all data.&lt;/P&gt;

&lt;P&gt;Any idea what is wrong ?&lt;BR /&gt;
Philippe&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 19:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291395#M55539</guid>
      <dc:creator>Lenval06</dc:creator>
      <dc:date>2017-05-12T19:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291396#M55540</link>
      <description>&lt;P&gt;search index=cisco | head &lt;BR /&gt;
look on the left part of the screen &lt;BR /&gt;
the 3 fields host, source, sourcetype supposed to be there&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 20:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291396#M55540</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-12T20:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291397#M55541</link>
      <description>&lt;P&gt;You are right Adonio, when I run this query I get this result.&lt;/P&gt;

&lt;P&gt;What I meant the "Search" page which shows all Hosts added,...and the moment I have the message "No data has been added",,,,whereas I should have the hostname on my cisco device.&lt;/P&gt;

&lt;P&gt;Any idea ?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 20:42:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291397#M55541</guid>
      <dc:creator>Lenval06</dc:creator>
      <dc:date>2017-05-12T20:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291398#M55542</link>
      <description>&lt;P&gt;you mean the data summary button?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 20:45:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291398#M55542</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-12T20:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291399#M55543</link>
      <description>&lt;P&gt;I mean the default page when you open Splunk: you have a list of "Hosts" , then if you click "Sources" you can see all your sources are are being indexed and finally if you click on "Sourcetypes" you can see all your sources types&lt;/P&gt;

&lt;P&gt;In this page, I do not have anything being displaying whereas I have data being received from a forwarder.&lt;/P&gt;

&lt;P&gt;Is this clearer ?&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 20:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291399#M55543</guid>
      <dc:creator>Lenval06</dc:creator>
      <dc:date>2017-05-12T20:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291400#M55544</link>
      <description>&lt;P&gt;hmmm, just noticed the question is tagged as splunk light.&lt;BR /&gt;
ill place some screenshots in an answer, hopefully the UI is similar but i am not 100% sure.&lt;BR /&gt;
anyways, i think all you need is to click the data summary button&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 22:16:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291400#M55544</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-12T22:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the forwarder but data is being received?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291401#M55545</link>
      <description>&lt;P&gt;here is in splunk enterprise, kindly assist with splunk light if its not equivalent:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2922iD26BDA03ABF2B07A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2923i0F6A8E6C7AA69B2E/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 22:20:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-see-the-forwarder-but-data-is-being-received/m-p/291401#M55545</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-12T22:20:13Z</dc:date>
    </item>
  </channel>
</rss>

