Splunk Enterprise

Logs not visible in splunk

VijaySrrie
Builder

Hi All,

User has configured to send the logs from his end to splunk via syslog method.

He has enabled debug logs at his end.

We are able to see the logs in Splunk Search Head (Log in /log out/ some other logs)

When user performs show command at his end --> Those logs are not seen in splunk.

May I know what is missing here?

Thanks,

Vijay Sri S

 

Labels (2)

blakem
Explorer

> We are able to see the logs in Splunk Search Head (Log in /log out/ some other logs)

> When user performs show command at his end --> Those logs are not seen in splunk.

From my understanding, your Splunk account when doing a search can see the logs, sent via syslog from some system. Another Splunk account when doing a search can't see the logs.

If that's correct, it's likely the other account isn't set to search the index they're going into by default, or doesn't have permissions to search the index they're going int.

If they have access, adding index=syslog (or whatever index the data is going to) to the start of your search string will search the data.

Default indexes to search are set in the roles area.

Index permissions are set in the index area.

VijaySrrie
Builder

No. 

No one is able to view the logs (person who has access to that particular index/admins), which user is referring to.

User executed the show commands and some other commands in front of us, but we are not able to see those logs in splunk, [User has enabled debug logs at his end, so all the logs should be visible in splunk]

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...