Hello, this is my forwarder inputs.conf looks like but I am unable to see any data in the second index cisco_asa.
index fortinet works just fine.
[default]
host = ABC
[monitor://D:\Syslog\Fortinet]
index = fortinet
sourcetype = fortigate
[monitor://D:\Syslog\ASA]
index = cisco_asa
sourcetype = cisco:asa
Please advise!
Based on your inputs, I am putting few ways where it might have gone wrong.
Above are some causes that make some indexed data not searchable. Please do a check and revert.
Can you see any data in index=fortinet?
Is there data in D:\Syslog\ASA?
Are there any relevant messages in the forwarder's splunkd.log?
Yes, I can see data in index=fortinet
However, I cannot see any data in index=cisco_asa
Yes, there is data is D:\Syslog\ASA