Getting Data In

Why is my auditd log data not appearing in Splunk and don't see any errors in splunkd.log on forwarder or indexers?

BT_Neophyte
Explorer

I've set up forwarding many times, but for some reason cannot get my auditd log to properly appear in Splunk. I'm banging my head against the wall and am probably just missing something simple.

I created a new app, which forwards the log I want and deployed it to the forwarder on my test server. I created an indexes.conf file for my indexers to handle the new Index. Data is being written to the log, but when I go into Splunk and search for that index, nothing is found. I'm not seeing any errors in splunkd.log on either the forwarder or the indexers. The Index was not showing up in the Search Head's webui under Settings->Indexes. I tried creating it there as well, but still to no avail.

Anyone know what I'm missing?

0 Karma

xdaxdb
Explorer

I'm guessing it has something to do with user roles / permissions on the user account you are searching with.

But, I am very new to splunk so I could be wrong

0 Karma

BT_Neophyte
Explorer

I'm an admin in Splunk so have access to everything, and while I was planning on locking down this Index, at this point there are no restrictions on who can search it.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...