Getting Data In

Data from forwarder arrives at the indexer but does not get indexed

chris
Motivator

Hi

I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for any data from that forwarder in splunk.

This is what I see in the metrics.log on the indexer: 03-03-2010 17:55:25.602 INFO Metrics - group=tcpin_connections, :61464:9997, connectionType=cooked, sourcePort=61464, sourceHost=, sourceIp=, destPort=9997, _tcp_Bps=6.39, _tcp_KBps=0.01, _tcp_avg_thruput=13.09, _tcp_Kprocessed=8166.00, _tcp_eps=0.03

Is there a way to find out where the data went that arrived on the indexer?

Tags (3)
1 Solution

dskillman
Splunk Employee
Splunk Employee

Chances are you have the forwarder inputs set to use an index that doesn't exist on the indexer. Check your inputs.conf file and see what "index =". Add that index to the indexer and your data should show up.

DJ

View solution in original post

0 Karma

dskillman
Splunk Employee
Splunk Employee

Chances are you have the forwarder inputs set to use an index that doesn't exist on the indexer. Check your inputs.conf file and see what "index =". Add that index to the indexer and your data should show up.

DJ

0 Karma

chris
Motivator

The index did exist on the indexer, I reinstalled the agent among other things. I can't say what was wrong in the end. This is a list of things I check to get forwarders running: Splunk user must have read access to the files that will be monitored, Correct server configured in outputs.conf, "INFO TcpInputProc - Connection accepted from" Messages in splunkd.log on the indexer, Check for Messages in metrics.log on the indexer, Query splunk for events you expect

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...