Getting Data In

Splunk Hosts Not Showing Up

lmalhoit
Explorer

I have one Splunk receiver set up and several forwarders (forwarders using free version). About 9 of my hosts are listed under Hosts in the Search panel, but quite a few aren't. They're set up the same way as the 9 that are showing up with my dns name followed by port 9997. It's been a few days and I know there have been events that would be logged in splunk by now.

Any suggestions? This is a mix of Windows 2003 and 2008 servers. I have an eval license which allows for 10GB of data, so it's not a licensing issue.

Thanks in advance!

Tags (2)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hello lmalhoit

have you tried to connect from one of the 'missing' hosts to your splunk 'receiver', like 'telnet 192.168.100.97 9997' ?

any firewall/ipsec blocking traffic?

lmalhoit
Explorer

Yes, I've actually started working on this issue with a splunk tech. Telnet works fine and everything is on the same subnet inside my network...no firewalls in between.
Thanks!

0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

A license issue wouldn't prevent the data from indexing. You can search the internal index to see if there are isues with those hosts:

index=_internal sourcetype=splunkd
0 Karma

lmalhoit
Explorer

I ran the search you asked me to. I'm not seeing anything weird in the logs. I went through quite a bit of it. There was one mention of one of the hosts that seems to be missing and that was about it. It wasn't any kind of error either. This is what is said:
02-21-2011 09:16:58.666 INFO Metrics - group=tcpin_connections, 192.168.100.97:4981:9997, connectionType=cooked, sourcePort=4981, sourceHost=hostname.domain.org, sourceIp=192.168.100.97, destPort=9997, _tcp_Bps=6.39, _tcp_KBps=0.01, _tcp_avg_thruput=0.03, kb=0.19, _tcp_Kprocessed=15513.00, _tcp_eps=0.03

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...