Getting Data In

We are receiving _internal logs from universal forwarders but we are not receiving data from indexes which are created externally???

saisrujan28
Explorer

Universal forwarder sending data _internal logs and we are receiving those logs and appeared on search heads.

But we deployed an add-on on the same universal forwarder. But we are not receiving data from the index which is present in the add-on. We created index on indexers.we are receiving data to this index from other UF's.
After deploying add-on we restarted UF

Example: index=_internal host=abc (we are getting splunkd logs)

index= test1 host=abc (we are not able see any logs)

can any one explain why this happens??

Tags (1)
0 Karma

micahkemp
Champion

Which addon did you deploy? Does this addon set the host value based on the event payload? Did you enable the inputs?

You may want to start by including your inputs.conf from the forwarder to enable additional help.

0 Karma

ansif
Motivator

Dont you see any clue from Indexer and UF _internal logs.Just search for this indexname as keyword.

0 Karma

somesoni2
Revered Legend

Obviously something is not configured properly for your non-internal data monitoring. I would suggest going through this post for troubleshooting steps.
http://docs.splunk.com/Documentation/Splunk/7.0.1/Troubleshooting/Cantfinddata

0 Karma

saisrujan28
Explorer

we have checked diag file from universal forwarder everything configured properly

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...