Getting Data In
Highlighted

How to see Events coming into the Indexer?

Path Finder

I am forwarding events from windows events from Graylog to a load balance point in front of a UF using a TCP input then forwarding to my indexers. I can see in the metrics.log on the UF that data is coming in and I can see on the indexer data coming in from the IP of of my UF. When I search i am not seeing that sourcetype.

Where can I look to see what might be happening on the indexer?

Thanks!

0 Karma
Highlighted

Re: How to see Events coming into the Indexer?

SplunkTrust
SplunkTrust

An amazing read is this Splunk doc page for these type of troubleshooting:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Cantfinddata

Highlighted

Re: How to see Events coming into the Indexer?

SplunkTrust
SplunkTrust

@pfabrizi,

how does the inputs.conf on your UF and on your indexer look like?

Please post the contents of those files.

0 Karma
Highlighted

Re: How to see Events coming into the Indexer?

Path Finder

what ever the issue was it is resolved. I think they are throttling the graylog events and I just didn't wait long enough.

Thanks!

0 Karma