Hi all,
I have install splunk forwarder in 1 centos device, sending to indexer.
From the search head, i can see data from this host but the the index is put as Main.
On the app, we have already specify to another index and we verified that the index is created.
Anybody know what am i missing? Already restart splunk services for both host and searchhead.
Double-check the query and settings. The btool output shown is for source /var/log/messages, but the query is showing source=/var/log/cron.
Yea i know, I am just showing an example.
This is the actual settings.
This is the settings in the inputs.conf. Strangely, this is set to disabled but we are receiving from this source.
If you're receiving data for a disabled input then the inputs.conf either has not been loaded (restart the forwarder) or is overridden by another inputs.conf file (btool should show that). The same goes for data being sent to the wrong index.
I mean for the /var/log/cron. And strangely, all my /var/logs/messages path are also not sending since this morning. i do not know what i did