Getting Data In

I've setup a forwarder on Windows. My receiver is enabled and running tcpdump shows connection. However, Splunk is not indexing data.

bigfatyeastroll
Path Finder

one of my team has installed the forwarder on a Windows client. running tcpdump on the backend of splunk enterprise shows:

08:32:06.990056 IP xxx.56097 > splunk.xxx.9997: Flags [P.], seq 777:895, ack 1, win 512, length 118
08:32:06.990080 IP splunk.xxx.9997 >xxx.56097: Flags [.], ack 895, win 2512, length 0

my receiver is enabled on port 9997 but Splunk is not indexing the data. I have other clients using the same setup and they are being indexed.

Thoughts/Suggestions?

0 Karma
1 Solution

bigfatyeastroll
Path Finder

The forwarder was not setup using the Domain Admin and using the Domain\Username style. Thank!

View solution in original post

0 Karma

bigfatyeastroll
Path Finder

The forwarder was not setup using the Domain Admin and using the Domain\Username style. Thank!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarder has inputs enabled and that those inputs reference indexes that exist.

---
If this reply helps you, Karma would be appreciated.
0 Karma

bigfatyeastroll
Path Finder

Could it be something in the setup during the installation of the Forwarder?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...