Deployment Architecture

After configuring Splunk application logs, why are they not ingesting even after restarting?

New Member


I have configured application logs on one of the server, but the logs are not ingested in splunk even after restarting the splunk service.

Configured log locations exists and there were no errors in splunkd.log also.

Can someone suggest on this.

I have also tried out below debug commands where the output return the log location i have configured.

1.C:\Program Files\SplunkUniversalForwarder\bin\splunk btool inputs list --debug and
2.C:\Program Files\SplunkUniversalForwarder\bin\splunk list monitor

0 Karma



Please refer these troubleshooting steps:

Let me know if this helps!!

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!