Splunk Enterprise

Splunk app for Logbinder - Event Entries empty

juerchri
New Member

Hi guys,

I installed Supercharger, Splunk and Splunk app for Logbinder in order to configure log forwarders and have them visualized within Splunk (like here https://support.logbinder.com/SuperchargerKB/50135/8-Install-Supercharger-with-Splunk-Light-and-the-...)
So far everything worked flawless, Events are forwarded and collected but when looking at the event entries in Splunk they are not showing any data:

alt text

When looking inside the forwarded Events everything looks as it should, only what is displayed in Splunk is wrong.
Help really appreciated!

Thanks and Regards

One additional question: The forwarded events are stored in a event file. Are they also stored within the SQL DB which Logbinder creates? Only relying on this file seems a bit crazy to me? How is Splunk crawling this file?

Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...