Getting Data In

Why is a Specific Sourcetype Not Flowing to Splunk Enterprise?

kburtch
New Member

My company uses Splunk and we just migrated everything from Cloud Splunk over to Splunk Enterprise.

 

We manage quite a few servers and they are all configured similarly, however, a handful of them are not flowing their logs to Splunk, even with a specified inputs.conf in /opt/splunkforwarder/etc/system/local/inputs.conf.

 

The file path that is specified in the Sourcetype within the inputs.conf file is identical to servers that are flowing properly.

 

Where might I be missing some information possibly?

Labels (4)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you also proper outputs.conf on those servers? Have you gotten UF’s internal logs to your splunk server?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...