My company uses Splunk and we just migrated everything from Cloud Splunk over to Splunk Enterprise.
We manage quite a few servers and they are all configured similarly, however, a handful of them are not flowing their logs to Splunk, even with a specified inputs.conf in /opt/splunkforwarder/etc/system/local/inputs.conf.
The file path that is specified in the Sourcetype within the inputs.conf file is identical to servers that are flowing properly.
Where might I be missing some information possibly?
Have you also proper outputs.conf on those servers? Have you gotten UF’s internal logs to your splunk server?