Splunk Enterprise

How to fix the red health?

airmansavath
Engager

Yes, I'm new to this Splunk stuff and I'm trying to learn and I have a health red and I'm not sure how to fix it and i don't know if it's causing me other issues 

 

here are the list that are marked in red. 

 

splunkd

 

Data Forwarding
Splunk-2-Splunk Forwarding
TCPOutAutoLB-0
File Monitor Input

Ingestion Latency
Real-time Reader-0
 
 
also I'm currently am taking some online courses from Udemy. would anyone  recommend anything else or where to learn?  I'm only asking because these courses are out of date. 
 
 
Labels (2)
0 Karma

stlouissplunk
New Member

i am currently taking udemy classes also and my splunk enterprise health is in the red. who can help me with this?

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We can't help you fix what's wrong without knowing what is wrong.  "Red health" could be caused by any of many things (or multiple things).  Click on the read health icon to show the health status and then click on each red icon to get details about what is wrong (or what Splunk thinks is wrong - sometimes it's wrong about that).  Pass on that information and someone should be able to help you fix it.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...