Security

Receiving Data on Splunk Server

AmyShah
Loves-to-Learn

 

I am unable to receive data from the forwarder to the server However I have added the server

on server I got

netstat -auntp | grep 9997

tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN
tcp 0 0 myserver:9997 ServerIP:60992 ESTABLISHED

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AmyShah,

if you're not receiving data from a Forwarder you have at first to check if you did all the configuration steps:

If you did all the above configuration steps, you have to check, if you're receiving logs.

At first check if you're receiving the Splunk internal logs:

index=_internal host=<your_host>

If yes, the problem is that you have to configure inputs  (https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps) or there's a problem on them.

If not, check again the connection.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...