Security

Receiving Data on Splunk Server

AmyShah
Loves-to-Learn

 

I am unable to receive data from the forwarder to the server However I have added the server

on server I got

netstat -auntp | grep 9997

tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN
tcp 0 0 myserver:9997 ServerIP:60992 ESTABLISHED

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AmyShah,

if you're not receiving data from a Forwarder you have at first to check if you did all the configuration steps:

If you did all the above configuration steps, you have to check, if you're receiving logs.

At first check if you're receiving the Splunk internal logs:

index=_internal host=<your_host>

If yes, the problem is that you have to configure inputs  (https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps) or there's a problem on them.

If not, check again the connection.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...