Security

Receiving Data on Splunk Server

AmyShah
Loves-to-Learn

 

I am unable to receive data from the forwarder to the server However I have added the server

on server I got

netstat -auntp | grep 9997

tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN
tcp 0 0 myserver:9997 ServerIP:60992 ESTABLISHED

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AmyShah,

if you're not receiving data from a Forwarder you have at first to check if you did all the configuration steps:

If you did all the above configuration steps, you have to check, if you're receiving logs.

At first check if you're receiving the Splunk internal logs:

index=_internal host=<your_host>

If yes, the problem is that you have to configure inputs  (https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps) or there's a problem on them.

If not, check again the connection.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...