Installation

How to fix Splunk index pipeline?

Solo69
Observer

Have anyone an idea how to fix this? 

Solo69_0-1689948227135.png

Any suggestion? Thank you

 

 

Labels (1)
Tags (2)
0 Karma

m_pham
Splunk Employee
Splunk Employee

Try going into your monitoring console app > Settings > General Setup - then click on Apply Changes to see if that fixes your issue.

m_pham_0-1690921482088.png

Double check this page again to be safe: https://docs.splunk.com/Documentation/Splunk/9.1.0/DMC/Configureindistributedmode

 

0 Karma

Solo69
Observer

Worked. Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Solo69,

this should be the Monitoring Console that works with internal logs, did you forwarded internal log of that machine to your indexers?

Ciao.

Giuseppe

0 Karma

Solo69
Observer

They're forwarding their internal logs

0 Karma

Simple_Search
Path Finder

Are permissions interfering with your implementation - Are all files owned by splunk:splunk or does root have ownership of some items?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...