Getting Data In

Why is my forwarder not forwarding data other than _internal?

sathiyasun
Explorer

I have forwarder not forwarding any input data other than _internal.

Checks performed:
splunk version - 6.4.2
Forwarder is up and running.
Checked the $SPLUNK_HOME/etc/system/local/inputs.conf . -- Checked the host name
Checked the $SPLUNK_HOME/etc/system/local/deploymentclient.conf
Checked the $SPLUNK_HOME/etc/system/local/server.conf
I don't see any error/warning in splunkd.log.
File path for the log files.

I have restarted the forwarder several times but no luck.
The inputs in the /etc/app are not forwarding.

Please advise.

0 Karma

pradeepkumarg
Influencer

Does the log files have data in them to forward?
Cross check the path for any type-o ?

0 Karma

sathiyasun
Explorer

Fixed, There was an mistake in the inputs whitelist. It works now. Thanks.

0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...