<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hosts not visible in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323969#M163420</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Configured splunk universal forwarders on windows &amp;amp; linux hosts through splunk deployment server, which are visible, when check under settings--&amp;gt; Forward Mgmt but when trying to check the hosts under Search &amp;amp; Reporting--&amp;gt;Data Summary when clicked, the hosts are not visible.&lt;/P&gt;

&lt;P&gt;Appreciate if any one can help with how to add or configure hosts to be visible under Data summary.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2018 02:48:36 GMT</pubDate>
    <dc:creator>rajballa</dc:creator>
    <dc:date>2018-01-23T02:48:36Z</dc:date>
    <item>
      <title>hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323969#M163420</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Configured splunk universal forwarders on windows &amp;amp; linux hosts through splunk deployment server, which are visible, when check under settings--&amp;gt; Forward Mgmt but when trying to check the hosts under Search &amp;amp; Reporting--&amp;gt;Data Summary when clicked, the hosts are not visible.&lt;/P&gt;

&lt;P&gt;Appreciate if any one can help with how to add or configure hosts to be visible under Data summary.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 02:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323969#M163420</guid>
      <dc:creator>rajballa</dc:creator>
      <dc:date>2018-01-23T02:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323970#M163421</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is it single server deployment OR distributed environment? &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 12:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323970#M163421</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-01-23T12:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323971#M163422</link>
      <description>&lt;P&gt;hey @rajballa&lt;/P&gt;

&lt;P&gt;You will be able to see hosts under data summary only when you are monitoring any files.From the description you have given, I think you have only configured forwarders.You need to add monitor inputs as well.&lt;BR /&gt;
Well if you want to see if your forwarder is configured properly then you can run this command.If you getting data after running this command means you have configured your forwarder correctly&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=&amp;lt;your_host&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 13:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323971#M163422</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-23T13:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323972#M163423</link>
      <description>&lt;P&gt;Hi mayurr98,&lt;/P&gt;

&lt;P&gt;thanks, using the above command it displays the data if I set the time as "Last 30 days". but as said when I click on Data Summary button, the hosts are not visible.&lt;/P&gt;

&lt;P&gt;Can you help with the steps on how to add monitor inputs.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 23:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323972#M163423</guid>
      <dc:creator>rajballa</dc:creator>
      <dc:date>2018-01-23T23:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323973#M163424</link>
      <description>&lt;P&gt;It is a single server deployment&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 03:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323973#M163424</guid>
      <dc:creator>rajballa</dc:creator>
      <dc:date>2018-01-24T03:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323974#M163425</link>
      <description>&lt;P&gt;follow this doc if you want to index local files from the indexer&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorfilesanddirectorieswithSplunkWeb"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorfilesanddirectorieswithSplunkWeb&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;if you have forwarder which is at the remote location then follow this doc&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorfilesanddirectoriesusingtheCLI#Example_1:_Monitor_files_in_a_directory"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorfilesanddirectoriesusingtheCLI#Example_1:_Monitor_files_in_a_directory&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 06:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323974#M163425</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-24T06:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323975#M163426</link>
      <description>&lt;P&gt;Thank you mayurr98.&lt;BR /&gt;
I have the same document too. Since I am new to this splunk, when trying to use the steps specified in the said doc, not able to understand - what to select - when click browse button under files and directories.&lt;/P&gt;

&lt;P&gt;Not able to select the host.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 06:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323975#M163426</guid>
      <dc:creator>rajballa</dc:creator>
      <dc:date>2018-01-24T06:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: hosts not visible</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323976#M163427</link>
      <description>&lt;P&gt;you are confusing your self if your host is at the remote location i.e. on the forwarder then you have to do using CLI. you need to have a file to index something. refer the second doc that I gave. &lt;/P&gt;

&lt;P&gt;you need to execute &lt;CODE&gt;./splunk add monitor &amp;lt;path of file&amp;gt;&lt;/CODE&gt; on the forwarder.&lt;BR /&gt;
and you do not need to select the host . Splunk will take it automatically. using Splunk web you can monitor files of the local machine only.and there as well do not need to select any host.&lt;BR /&gt;
If you want to  load any sample data then look for below doc&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/PivotTutorial/GetthetutorialdataintoSplunk"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/PivotTutorial/GetthetutorialdataintoSplunk&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 07:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hosts-not-visible/m-p/323976#M163427</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-24T07:07:26Z</dc:date>
    </item>
  </channel>
</rss>

