Monitoring Splunk

Missing Internal Logs from Server

BRFZ
Communicator

Hello,

I have a server configured with three roles: Deployment Server, Console Monitoring, and License Master. However, I am not receiving the internal and audit logs from this server, such as logs from the Search Head or Indexers.

If you have any solutions to this problem, I would greatly appreciate your help.

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @BRFZ ,

did you configured this server to send logs to the Indexers?

did you opened the firewall routes between this server and Indexers on the port 9997?

Make these checks.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @BRFZ ,

did you configured this server to send logs to the Indexers?

did you opened the firewall routes between this server and Indexers on the port 9997?

Make these checks.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...