Getting Data In

How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

vad34
Path Finder

Hello guys,

I have new Splunk 6.3.1 installation on Centos 6.7.
After installation, there are no events coming to Splunk. I reinstalled Splunk, but still no data..
I configured data inputs and the index, but with no luck.
Another installation with Splunk 6.2.3 on Linux CentOS 6.6 works fine.

Any ideas?
Tnx in advance

0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

Using the Splunk admin account, verify first that you see data being ingested on the indexer e.g. splunkd.log from the indexer.

index=_internal source=*splunkd.log

If you are getting data here the indexer is ingesting data from its own local monitors. Since it is new install next check to ensure you have configured a receiving port. So other Splunk instances can send data to the indexer.

0 Karma

vad34
Path Finder

Tnx for the reply, yes the data indexed on internal source and i am able to see local linux logs.
When it comes to Win & Linux remote machine i got NO data events.
I installed splunk 6.2.3 instead splunk 6.3.1 but still the same issue (

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...