Monitoring Splunk

I am cloning _json sourcetype on managed splunk cloud to new custom name , the logs are not coming from log4j configuration

Nikhilsplunker
New Member

I have cloned a _json sourcetype to a custom sourcetype name and gave the correct URI for managed splunk cloud , still not being able to send logs to managed splunkcloud . I have also created a custom sourcetype cloning json_no_timestamp , it works, what are we missing
1) Is the issue on sourcetype definition or log4j configuration?
2) How to correct it ?

Tags (1)
0 Karma

Nikhilsplunker
New Member

Thanks will have a look and post back

0 Karma

woodcock
Esteemed Legend

We need more detail. In any case, check the error logs for splunkd and there is probably something there that you can fix.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...