Getting Data In

Active forwards: 10.20.30.40:9997 Configured but inactive forwards: None

rahul2gupta
Path Finder

Hi,

When I ran the command ./splunk list forward-server , we are getting below error message.

Active forwards:
10.20.30.40:9997
Configured but inactive forwards:
None

Can you please help me to troubleshoot the below error?

Regards,

Rahul Gupta

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

What is your error? This said that you have configured one forwarder which are currently in use?

0 Karma

rahul2gupta
Path Finder

Hi @isoutamo ,

logs are not getting ingested into splunk.

Regards,

Rahul

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Is that a correct address for your indexer?

Did you see internal logs from that forwarder or other FWDs?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...