Getting Data In

How to see the logs of the second forwarders logs? (Using two forwarders and one indexer)

aatik5u
Path Finder

Hello there,

I am working on VMware, I have two linux machines that I'm using as universal forwarders (ubuntu desktop and a linux server that are configured in the exact same way as forwarders). I have another linux machine that I'm using as an indexer.

The thing is that one of my forwarders (linux server) is forwarding correctly to the indexer, and i can see all the information i need in the index main. BUT the second forwarder logs are nowhere to be found. Although I can see the 2nd universal forwarder when I type index=_internal in the search bar but this index doesn't show any logs.

Can someone help me please so I can see the logs of the second forwarders logs?

Have a great day everyone!

Abir

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aatik5u,

if you can see both the forwarders, this means that the connection is correctly established.

The problem could be at input level: how do you configured inputs on Forwarders?

did you used a TA (e.g. TA_Linux) or what else?

You can sse this in the $SPLUNK_HOME/etc/apps folder of Forwarders: there are some common apps installed by Splunk and some apps installed to take logs e.g. TA_Linux (https://splunkbase.splunk.com/app/833/).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...