Installation

How to fix Splunk index pipeline?

Solo69
Observer

Have anyone an idea how to fix this? 

Solo69_0-1689948227135.png

Any suggestion? Thank you

 

 

Labels (1)
Tags (2)
0 Karma

m_pham
Splunk Employee
Splunk Employee

Try going into your monitoring console app > Settings > General Setup - then click on Apply Changes to see if that fixes your issue.

m_pham_0-1690921482088.png

Double check this page again to be safe: https://docs.splunk.com/Documentation/Splunk/9.1.0/DMC/Configureindistributedmode

 

0 Karma

Solo69
Observer

Worked. Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Solo69,

this should be the Monitoring Console that works with internal logs, did you forwarded internal log of that machine to your indexers?

Ciao.

Giuseppe

0 Karma

Solo69
Observer

They're forwarding their internal logs

0 Karma

Simple_Search
Path Finder

Are permissions interfering with your implementation - Are all files owned by splunk:splunk or does root have ownership of some items?

0 Karma
Get Updates on the Splunk Community!

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...