Getting Data In
Highlighted

How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

Path Finder

Hello guys,

I have new Splunk 6.3.1 installation on Centos 6.7.
After installation, there are no events coming to Splunk. I reinstalled Splunk, but still no data..
I configured data inputs and the index, but with no luck.
Another installation with Splunk 6.2.3 on Linux CentOS 6.6 works fine.

Any ideas?
Tnx in advance

0 Karma
Highlighted

Re: How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

Communicator

Using the Splunk admin account, verify first that you see data being ingested on the indexer e.g. splunkd.log from the indexer.

index=_internal source=*splunkd.log

If you are getting data here the indexer is ingesting data from its own local monitors. Since it is new install next check to ensure you have configured a receiving port. So other Splunk instances can send data to the indexer.

0 Karma
Highlighted

Re: How to troubleshoot why no events are getting indexed in Splunk 6.3.1 on Linux CentOS 6.7?

Path Finder

Tnx for the reply, yes the data indexed on internal source and i am able to see local linux logs.
When it comes to Win & Linux remote machine i got NO data events.
I installed splunk 6.2.3 instead splunk 6.3.1 but still the same issue (

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.