Reporting

PingFederate App Forwarded Events goto Splunk_Audit_Too_Small

lew00
New Member

Hi have a new install with a single Splunk server for evaluation.  I set up the universal forwarder and the Splunk service on Centos and updated the PingFederate to create the require splunk audit file.  I then configured the receiver and the sender to use the /opt/pf/pingfederate/log/splunk_audit.log

 

Entries started to flow from the forwarder to the Splunk indexer but all the PingFederate App panes show "waiting for input".  From the search I see the data event flowing but they all say Splunk_Audit_Too_Small

Any Tips how to fix this?

 

Thanks!

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...