All Apps and Add-ons

How to see which indexes is reciving log from certain forwarder?

anshuman19
Explorer

I have set index=new in inputs.conf file in forwarder but my new have no logs so I think its going to some where else when I check other indexes like main internal its shows some log .So how to configure the forwarder so it send to right indexer.
I installed splunk add-on on 29/1/2018 form that date Index=os is not receiving any thing and when I run setup.sh and try to enable inputs its send me message "enable failed". I think the both problem are related some how , can anyone help me in this

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi anshuman19,
if you're speaking of Universal Forwarders, you have to troubleshoot data ingestion (see https://docs.splunk.com/Documentation/Forwarder/7.0.2/Forwarder/Troubleshoottheuniversalforwarder ).

Anyway, the first thing is to check on Forwarder:

  • if connection is open, using telnet indexer_address 9997 and telnet deployment_server_address 8089;
  • $SPLUNK_HOME/etc/system/local/deploymentclient.conf and verify if it's configured your Deployment Server;
  • $SPLUNK_HOME/etc/system/local/outputs.conf and check if your Indexes are correctly addressed;
  • $SPLUNK_HOME/etc/system/local/server.conf and inputs.conf and check what's the hostname and if there are more Forwarders with the same name.

After on indexer you can check on _internal if you're receiving logs:

index=_internal host=your_forwarder_hostname

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi anshuman19,
if you're speaking of Universal Forwarders, you have to troubleshoot data ingestion (see https://docs.splunk.com/Documentation/Forwarder/7.0.2/Forwarder/Troubleshoottheuniversalforwarder ).

Anyway, the first thing is to check on Forwarder:

  • if connection is open, using telnet indexer_address 9997 and telnet deployment_server_address 8089;
  • $SPLUNK_HOME/etc/system/local/deploymentclient.conf and verify if it's configured your Deployment Server;
  • $SPLUNK_HOME/etc/system/local/outputs.conf and check if your Indexes are correctly addressed;
  • $SPLUNK_HOME/etc/system/local/server.conf and inputs.conf and check what's the hostname and if there are more Forwarders with the same name.

After on indexer you can check on _internal if you're receiving logs:

index=_internal host=your_forwarder_hostname

Bye.
Giuseppe

DUThibault
Contributor

I'd first check to make sure the forwarder is registered with the indexer. Does it show up in Settings: (Distributed environment) Forwarder management? Next check what is being watched by the forwarder. Check if the 'new' index exists ( Settings: (Data) Indexes).

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...