Getting Data In

How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

vad34
Path Finder

Hello guys,

I have new Splunk 6.3.1 installation on Centos 6.7.
After installation, there are no events coming to Splunk. I reinstalled Splunk, but still no data..
I configured data inputs and the index, but with no luck.
Another installation with Splunk 6.2.3 on Linux CentOS 6.6 works fine.

Any ideas?
Tnx in advance

0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

Using the Splunk admin account, verify first that you see data being ingested on the indexer e.g. splunkd.log from the indexer.

index=_internal source=*splunkd.log

If you are getting data here the indexer is ingesting data from its own local monitors. Since it is new install next check to ensure you have configured a receiving port. So other Splunk instances can send data to the indexer.

0 Karma

vad34
Path Finder

Tnx for the reply, yes the data indexed on internal source and i am able to see local linux logs.
When it comes to Win & Linux remote machine i got NO data events.
I installed splunk 6.2.3 instead splunk 6.3.1 but still the same issue (

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...