Getting Data In

Forwarder is working but data is not shown in splunk

ASISH_9
Engager

Hi,

We have a setup in a remote machine that receives data from database in form of excel sheets and forwards it to Splunk environment
with the help of a universal forwarder.
But when i am searching that particular data it is not coming in splunk. Any idea why this is happening even if the .conf files are fine?

Tags (1)
0 Karma

woodcock
Esteemed Legend

There are a ton of reasons.

Is splunk running?
Is inputs.conf configured to send anything?
Is outputs.conf configured to show where to send it?
Does the forwarder have a route to the indexer hosts?
Do the firewalls and  other network equipment allow connections from the UF to the indexers (port 9997 or maybe 9998 or ???)?
Is _time correct for your events (maybe being thrown into the future)?
Are you indexers setup to receive anything?
0 Karma

hardikJsheth
Motivator
0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...