Alerting

No Data in Search App

macleadg
New Member

I installed a Splunk search head on my Windows machine.  I installed a forwarder on a RHEL8 VM hosted by the same machine.  The forwarder monitors /var and /etc.  The systems can ping each other, and ports 9997 and 8089 are open.  I have restarted Splunk on both systems.  No errors occurred during installation or on any other operation, but no data appears on the search head.

Please help.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

What about permissions?

may be user which is running splunk forwarder doesn’t have read access to those files under var.

with root on rhel:

setfacl -m u:splunkuser:r /var/log/secure

restart splunk you should see ssh logs from rhel8.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...