Getting Data In

Not getting any Data with Xenapp.

joefixit71
New Member

I installed a Instance of Splunk, setup 3 servers with the forwarders installed pointing to the main instance on port 9997. (License server, XenApp Data Collector/Xml broker and regular Xenapp server. I copied the folders for the snapins for each type of server to the "C:\Program Files\SplunkUniversalForwarder\etc\deployment-apps" The Index is installed for xenapp since it gets installed during the xenapp snapin install but its not receiving any data.
I get the message "no matching fields exist" on top and "No results found" I don't see any Farms listed to click on so its not even connecting to the Farm servers I tried to add. I don't have any firewalls in between so its not blocking any ports. I setup a receiver listening on port 9997 on the Main instance but still no data.
This below is the Output file of a server thats forwarding data.
[tcpout]
defaultGroup = default-autolb-group

[tcpout-server://nwnifictx040.usa-ed.net:9997]

[tcpout:default-autolb-group]
disabled = false
server = nwnifictx040.usa-ed.net:9997,nwnifictx040:9997

[tcpout-server://nwnifictx040:9997]

This is a server forwarding data's Input file
[default]
host = NWNIFICTX030

let me know if any other information is needed.

This is a evaluation setup that I was really trying to get a good look at before tomorrow.
thanks,
Matt

0 Karma

joefixit71
New Member

I did that from the powershell command window and still "no results found"

0 Karma

joefixit71
New Member

Still not seeing any data after i copied to the correct directory and restarted the splunk service everywhere.. I actually saw a graph look like it was goin to start then it went away..

0 Karma

joefixit71
New Member

Still not seeing any data after i copied to the correct directory and restarted the splunk service everywhere.. I actually saw a graph look like it was goin to start then it went away..

0 Karma

jconger
Splunk Employee
Splunk Employee

The snapins should go in "C:\Program Files\SplunkUniversalForwarder\etc\apps"

0 Karma

joefixit71
New Member

Still not seeing any data after i copied to the correct directory and restarted the splunk service everywhere.. I actually saw a graph look like it was goin to start then it went away..

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...