<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot View data in Splunk Console in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312148#M166258</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;yes . We have output.conf file  on forwarder server &lt;/P&gt;

&lt;P&gt;ServerB #cat outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = ServerA:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://ServerA:9997]&lt;/P&gt;</description>
    <pubDate>Fri, 01 Sep 2017 15:31:07 GMT</pubDate>
    <dc:creator>vivekg72</dc:creator>
    <dc:date>2017-09-01T15:31:07Z</dc:date>
    <item>
      <title>Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312143#M166253</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I am new to Splunk and we have to complete POC . We have two server : Server A ( Index Server where Splunk Enterprise is installed ) and Server B where we have installed Forwarder and configure it to monitor one file system &lt;/P&gt;

&lt;P&gt;Server B : &lt;/P&gt;

&lt;P&gt;Server B $&amp;gt; splunk list forward-server&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        ServerA:9997&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        None&lt;/P&gt;

&lt;P&gt;Server A : &lt;/P&gt;

&lt;P&gt;Server A &amp;gt; lsof -i TCP:9997&lt;BR /&gt;
COMMAND   PID           USER   FD   TYPE   DEVICE SIZE/OFF NODE NAME&lt;BR /&gt;
splunkd 20810 svc_splunk_dev   48u  IPv4 18875290      0t0  TCP *:palace-6 (LISTEN)&lt;BR /&gt;
splunkd 20810 svc_splunk_dev   79u  IPv4 18884788      0t0  TCP ServerA:palace-6-&amp;gt;ServerB:53122 (ESTABLISHED)&lt;/P&gt;

&lt;P&gt;ServerA # plunk list forward-server&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        None&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        None&lt;/P&gt;

&lt;P&gt;Please advise &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312143#M166253</guid>
      <dc:creator>vivekg72</dc:creator>
      <dc:date>2020-09-29T15:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312144#M166254</link>
      <description>&lt;P&gt;Hi vivekg72,&lt;BR /&gt;
what is your question? &lt;/P&gt;

&lt;P&gt;To send logs from a forwarder to an indexer see at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Data/WhatSplunkcanmonitor"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 12:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312144#M166254</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-01T12:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312145#M166255</link>
      <description>&lt;P&gt;Has your forwarder ever sent data to Splunk? If not, have you enabled your Splunk Enterprise server to listen on port 9997?&lt;/P&gt;

&lt;P&gt;You could also look under &lt;CODE&gt;/opt/splunk/var/log/splunk/splunkd.log&lt;/CODE&gt; for errors&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 13:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312145#M166255</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-01T13:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312146#M166256</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
No and there are no errors in splunkd.log file . Also  Splunk Enterprise server to listen on port 9997 is configured &lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
vivek&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 13:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312146#M166256</guid>
      <dc:creator>vivekg72</dc:creator>
      <dc:date>2017-09-01T13:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312147#M166257</link>
      <description>&lt;P&gt;Do you have an &lt;CODE&gt;outputs.conf&lt;/CODE&gt; defined on your forwarder which is pointing to your Splunk enterprise instance? If so, have you tested the connection between the two servers to verify there is not a firewall blocking them?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:25:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312147#M166257</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-01T15:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312148#M166258</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;yes . We have output.conf file  on forwarder server &lt;/P&gt;

&lt;P&gt;ServerB #cat outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = ServerA:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://ServerA:9997]&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:31:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312148#M166258</guid>
      <dc:creator>vivekg72</dc:creator>
      <dc:date>2017-09-01T15:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot View data in Splunk Console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312149#M166259</link>
      <description>&lt;P&gt;Did you restart splunkd after making changes to the conf files? Have you verified via telnet that your forwarder can connect to your Splunk instance? What is the location of your outputs.conf? &lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2017 12:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-View-data-in-Splunk-Console/m-p/312149#M166259</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-02T12:05:52Z</dc:date>
    </item>
  </channel>
</rss>

