Installation

How to fix Splunk index pipeline?

Solo69
Observer

Have anyone an idea how to fix this? 

Solo69_0-1689948227135.png

Any suggestion? Thank you

 

 

Labels (1)
Tags (2)
0 Karma

m_pham
Splunk Employee
Splunk Employee

Try going into your monitoring console app > Settings > General Setup - then click on Apply Changes to see if that fixes your issue.

m_pham_0-1690921482088.png

Double check this page again to be safe: https://docs.splunk.com/Documentation/Splunk/9.1.0/DMC/Configureindistributedmode

 

0 Karma

Solo69
Observer

Worked. Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Solo69,

this should be the Monitoring Console that works with internal logs, did you forwarded internal log of that machine to your indexers?

Ciao.

Giuseppe

0 Karma

Solo69
Observer

They're forwarding their internal logs

0 Karma

Simple_Search
Path Finder

Are permissions interfering with your implementation - Are all files owned by splunk:splunk or does root have ownership of some items?

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...