Getting Data In

Splunk server not recieving data from node

vysakhnubelity
New Member

I have a splunk enterprise server and a node configured with Linux forwarder. These are the things configured in both the ends:

server:
enabled port 9997 to be reciever
added the following in inputs.conf file
[splunktcp://9997]
disabled = 0

node:
added forward server and started forwarder
added the following in outputs.conf file
[tcpout:default-autolb-group]
server = 172.xx.x.xxx:9997

[tcpout-server://172.xx.x.xxx:9997]
added a custom folder to monitor list

But in Splunk web dashboard, I am not able to recieve any data from the node.
alt text

Can someone please help me..?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi vysakhnubelity,
you can follow Splunk documentation at https://docs.splunk.com/Documentation/Splunk/6.5.3/Forwarding/Receiverconnection

At first you should verify connection from the client:

telnet 172.xx.x.xxx 9997

so you can understand if there is the mandatory connectivity between Splunk servers.

After you should verify if indexer receives internal logs from forwarder:

index=_internal host=your_host

if there are internal logs, this means that you have to verify your log input otherwise that there is a connection problems between Splunk servers.

at least you should verify if date and time of both servers are aligned.

At this point, you should understand where is located the problem.

Bye.
Giuseppe

0 Karma

vysakhnubelity
New Member

Hello,

Thanks for the response. I verified that the connection exists and there's this audit data coming in to dashboard, I can see this once I click search and reporting and then on data summary.

But how can I get the same in the dashboard (I mean the home page when I login to Splunk Web)? In the above image, I should be able to select the instance and then the data appears below the same. How can I achieve this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...