Getting Data In

Not receiving logs from Syslog Server

damode
Motivator

I have set up a universal forwarder to read logs from kiwi syslog server.
Universal Forwarder is set to forward logs to the Indexer via Heavy Forwarder.
I have also set up the Heavy Forwarder as deployment server.
I have deployed the following inputs.conf to the U.F by deploying an app from the deployment server.

[monitor://C:\Program Files (x86)\Syslogd\Logs\x.x.x.x\log*.txt]
index = main
sourcetype = syslog
disabled = false

With all the above settings, I still cant see any logs on the Indexer.
I have confirmed following things already,

  1. U.F has the right privilege to read logs from syslog's log folder.
  2. network connection established between Syslog Server and H.F on H.F's port 9997 and 8089.
  3. receiving port 9997 on Indexer enabled.

splunk btool inputs list monitor command also does not work on the U.F
Please help me troubleshoot this.
Thank you.

0 Karma
1 Solution

damode
Motivator

There are only INFO messages.

Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.

Does restarting the U.F or splunk reload deploy-server both required to apply config settings on U.F ?

Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings-->Server Settings--> Deployment Client, it shows nothing at all. Any reason why ?

View solution in original post

damode
Motivator

There are only INFO messages.

Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.

Does restarting the U.F or splunk reload deploy-server both required to apply config settings on U.F ?

Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings-->Server Settings--> Deployment Client, it shows nothing at all. Any reason why ?

stefanhutchison
Explorer

Any messages in the splunkd.log file on the universal forwarder? It would be in Splunk_home\var\log\splunk\splunkd.log

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...