Installation

How to fix Splunk index pipeline?

Solo69
Observer

Have anyone an idea how to fix this? 

Solo69_0-1689948227135.png

Any suggestion? Thank you

 

 

Labels (1)
Tags (2)
0 Karma

m_pham
Splunk Employee
Splunk Employee

Try going into your monitoring console app > Settings > General Setup - then click on Apply Changes to see if that fixes your issue.

m_pham_0-1690921482088.png

Double check this page again to be safe: https://docs.splunk.com/Documentation/Splunk/9.1.0/DMC/Configureindistributedmode

 

0 Karma

Solo69
Observer

Worked. Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Solo69,

this should be the Monitoring Console that works with internal logs, did you forwarded internal log of that machine to your indexers?

Ciao.

Giuseppe

0 Karma

Solo69
Observer

They're forwarding their internal logs

0 Karma

Simple_Search
Path Finder

Are permissions interfering with your implementation - Are all files owned by splunk:splunk or does root have ownership of some items?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...