Getting Data In

Where to start debugging why Splunk receiver is not getting data from universal forwarder?

boris
Path Finder

From this line in the splunkd.log it appears the forwarder and receiver are connected?

/opt/splunkforwarder/var/log/splunk# vim splunkd.log 
04-02-2012 19:54:28.351 +0000 INFO  TcpOutputProc - Connected to idx=10.140.13.XX:9997

But I dont see any indication on the receiving splunk web application that it is receiving new data?

Where should I begin debugging?

1 Solution

ChrisG
Splunk Employee
Splunk Employee

There are some searches that might help you diagnose, see I can't find my data! in the Troubleshooting Manual.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

There are some searches that might help you diagnose, see I can't find my data! in the Troubleshooting Manual.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...