Getting Data In

Why isn't my Universal Forwarder data making it into the Indexer?

Path Finder

I have tried to set up a universialforwarder (first time from cli) and have it monitor some log files (/var/log/dhcpd.log for example)
The packets is being send and recived (checked with tcpdump on both end) but the host in not showing up in the splunk server. What kind of stuff should i start to check on the forwarder/server?

0 Karma

Path Finder

At a customer site I'm serving, 9 out of 10 problems with "missing data" is a mismatch between what is stated in the inputs.conf on the UF side and what is configured on the indexer side (i.e. the index you have in inputs.conf stanzas must also be present (and correctly configured) on the indexer side).

A quick way to determine if data is entering your indexes, is to check Manager -> Indexes. Locate your index and check the Earliest / Latest Event columns.

Depending on how your access controls with regards to accessing your indexes are configures, you might need to specify index= in the search field.

0 Karma

Splunk Employee
Splunk Employee

I would suggest that you look in splunkd.log under the $SPLUNK_HOME/var/log/splunk/ for messages that contain the ip address of the forwarder/indexer, depending on which place you are looking. That should give you some indication as to what is happening with your connection, and if it is successful.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...