Alerting

No Data in Search App

macleadg
New Member

I installed a Splunk search head on my Windows machine.  I installed a forwarder on a RHEL8 VM hosted by the same machine.  The forwarder monitors /var and /etc.  The systems can ping each other, and ports 9997 and 8089 are open.  I have restarted Splunk on both systems.  No errors occurred during installation or on any other operation, but no data appears on the search head.

Please help.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

What about permissions?

may be user which is running splunk forwarder doesn’t have read access to those files under var.

with root on rhel:

setfacl -m u:splunkuser:r /var/log/secure

restart splunk you should see ssh logs from rhel8.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...