Getting Data In

Active forwards: 10.20.30.40:9997 Configured but inactive forwards: None

rahul2gupta
Path Finder

Hi,

When I ran the command ./splunk list forward-server , we are getting below error message.

Active forwards:
10.20.30.40:9997
Configured but inactive forwards:
None

Can you please help me to troubleshoot the below error?

Regards,

Rahul Gupta

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

What is your error? This said that you have configured one forwarder which are currently in use?

0 Karma

rahul2gupta
Path Finder

Hi @isoutamo ,

logs are not getting ingested into splunk.

Regards,

Rahul

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Is that a correct address for your indexer?

Did you see internal logs from that forwarder or other FWDs?

0 Karma