Hi I have two linux virtual machines and i am trying to use splunk forwarder one linux to another. I am getting that "waiting for the results problem".
How can i fix this ?
Thnx a lot
Can you search for data in search and reporting on search head using following query
source=/var/log/auth.log if you are not able to see any data
run following command on forwarder where inputs configured to check active outputs configuration
/opt/splunkforwarder/bin/splunk list forward-server
it might ask to enter splunk admin crdentials
One doubt from my side
IP that you configured to send the data is indexer/search head or forwarder?.
if you tryitng to send the data to another forwader you wont be able to see any data on forwarder, you need to search data in splunk search head
Hi
you could list all your monitors on UF with command:
splunk list monitor
When you want to see status of those in UF you can see it with commands:
splunk list inputstatus |egrep -A5 '/var/log/auth.log'
r. Ismo
Is the forwarder running? Is it configured? What is in outputs.conf?
Don't waste your time with the Data Summary screen. Go to the Search & Reporting app and run a search to find the data.