I am forwarding events from windows events from Graylog to a load balance point in front of a UF using a TCP input then forwarding to my indexers. I can see in the metrics.log on the UF that data is coming in and I can see on the indexer data coming in from the IP of of my UF. When I search i am not seeing that sourcetype.
Where can I look to see what might be happening on the indexer?
Thanks!
@pfabrizi,
how does the inputs.conf on your UF and on your indexer look like?
Please post the contents of those files.
what ever the issue was it is resolved. I think they are throttling the graylog events and I just didn't wait long enough.
Thanks!
An amazing read is this Splunk doc page for these type of troubleshooting:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Cantfinddata