Try going into your monitoring console app > Settings > General Setup - then click on Apply Changes to see if that fixes your issue.
Double check this page again to be safe: https://docs.splunk.com/Documentation/Splunk/9.1.0/DMC/Configureindistributedmode
Worked. Thanks
Hi @Solo69,
this should be the Monitoring Console that works with internal logs, did you forwarded internal log of that machine to your indexers?
Ciao.
Giuseppe
They're forwarding their internal logs
Are permissions interfering with your implementation - Are all files owned by splunk:splunk or does root have ownership of some items?