Getting Data In

Can't feed data into Splunk

essibong1
New Member

I'm trying to know why I can't feed data in splunk. I'm trying to get data from windows servers to splunk, I've created a UF on the Windows server that has the data that needs to be forwarded to splunk. I've configured inputs and outputs.conf files on the forwarder and have also configured inputs.com file on the indexer, all ports are opened, everything is set but I'm still not getting data in splunk. Any help?

Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you verified the forwarder can connect to the indexer?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mloyola_splunk
Splunk Employee
Splunk Employee

Run this command to check if the forwarder is connected to the receiving instance.
"splunk list forward-server" , the indexer's ip should be in active state.

If its active , the next things to do is to check the splunkd.log of the universal forwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...