Getting Data In

Why my Index=”main” host=* command no results

holowolf3500
Loves-to-Learn

I am learning splunk for the first time in my course, I had this task of setting up 4 VMs through VMware workstation , 1 being controller a Centos GUI, and the other 3 being agents centos CLI. I went through the configuration of the VMs they all ping each other fine. I SSH the splunk onto the 4 VMs using mobaxterms. After creating the 9997 port on the controller and saving the port I configured each agent to have their agents ip address forward to the port of my controller. After going through my lab at the last part I had to type in an input Index=”main” host=* | table host | dedup host this had no results I was told if nothing popped up I would to troubleshoot by rebooting my vm and my host system but that didn't fix it would love some insights

image (4).png

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

As this sounds like you are asking answer for your course lab I just give pointers to you where you could find the answers.

I suppose that also your course material should give the answer what is missing/wrong on your configuration and how to debug it.

On comment for security. You should never run UF as a root on source node. Also don't use root as a splunk's internal admin user and never use the same password than you have in OS level.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...