I have set index=new in inputs.conf file in forwarder but my new have no logs so I think its going to some where else when I check other indexes like main internal its shows some log .So how to configure the forwarder so it send to right indexer.
I installed splunk add-on on 29/1/2018 form that date Index=os is not receiving any thing and when I run setup.sh and try to enable inputs its send me message "enable failed". I think the both problem are related some how , can anyone help me in this
Hi anshuman19,
if you're speaking of Universal Forwarders, you have to troubleshoot data ingestion (see https://docs.splunk.com/Documentation/Forwarder/7.0.2/Forwarder/Troubleshoottheuniversalforwarder ).
Anyway, the first thing is to check on Forwarder:
After on indexer you can check on _internal if you're receiving logs:
index=_internal host=your_forwarder_hostname
Bye.
Giuseppe
Hi anshuman19,
if you're speaking of Universal Forwarders, you have to troubleshoot data ingestion (see https://docs.splunk.com/Documentation/Forwarder/7.0.2/Forwarder/Troubleshoottheuniversalforwarder ).
Anyway, the first thing is to check on Forwarder:
After on indexer you can check on _internal if you're receiving logs:
index=_internal host=your_forwarder_hostname
Bye.
Giuseppe
I'd first check to make sure the forwarder is registered with the indexer. Does it show up in Settings: (Distributed environment) Forwarder management
? Next check what is being watched by the forwarder. Check if the 'new' index exists ( Settings: (Data) Indexes
).