Monitoring Splunk

Missing Internal Logs from Server

BRFZ
Communicator

Hello,

I have a server configured with three roles: Deployment Server, Console Monitoring, and License Master. However, I am not receiving the internal and audit logs from this server, such as logs from the Search Head or Indexers.

If you have any solutions to this problem, I would greatly appreciate your help.

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @BRFZ ,

did you configured this server to send logs to the Indexers?

did you opened the firewall routes between this server and Indexers on the port 9997?

Make these checks.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @BRFZ ,

did you configured this server to send logs to the Indexers?

did you opened the firewall routes between this server and Indexers on the port 9997?

Make these checks.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...