Getting Data In

Data doesnt show up on the screen

fkaanuslu
Loves-to-Learn

2021-08-19 19_13_12-Window.png2021-08-19 19_13_28-Window.png

 

Hi I have two linux virtual machines and i am trying to use splunk forwarder one linux to another. I am getting that "waiting for the results problem".

How can i fix this ?

Thnx a lot

 

 

 

Labels (1)
0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

@fkaanuslu 

Can you search for data in search and reporting  on search head using following query 

source=/var/log/auth.log  if you are not able to see any data 

 run following command on forwarder where inputs configured  to check active outputs configuration

/opt/splunkforwarder/bin/splunk list forward-server 
it might ask to enter splunk admin crdentials 

 

One doubt from my side 

IP that you configured to send the data is indexer/search head or forwarder?. 

if you tryitng to send the data to another forwader you wont be able to see any data on forwarder, you need to search data in  splunk search head 


0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could list all your monitors on UF with command:

splunk list monitor

When you want to see status of those in UF you can see it with commands:

splunk list inputstatus |egrep -A5 '/var/log/auth.log'

 r. Ismo

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the forwarder running?  Is it configured?  What is in outputs.conf?

Don't waste your time with the Data Summary screen.  Go to the Search & Reporting app and run a search to find the data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...