Alerting

No Data in Search App

macleadg
New Member

I installed a Splunk search head on my Windows machine.  I installed a forwarder on a RHEL8 VM hosted by the same machine.  The forwarder monitors /var and /etc.  The systems can ping each other, and ports 9997 and 8089 are open.  I have restarted Splunk on both systems.  No errors occurred during installation or on any other operation, but no data appears on the search head.

Please help.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

What about permissions?

may be user which is running splunk forwarder doesn’t have read access to those files under var.

with root on rhel:

setfacl -m u:splunkuser:r /var/log/secure

restart splunk you should see ssh logs from rhel8.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...