Splunk Enterprise

Splunk app for Logbinder - Event Entries empty

juerchri
New Member

Hi guys,

I installed Supercharger, Splunk and Splunk app for Logbinder in order to configure log forwarders and have them visualized within Splunk (like here https://support.logbinder.com/SuperchargerKB/50135/8-Install-Supercharger-with-Splunk-Light-and-the-...)
So far everything worked flawless, Events are forwarded and collected but when looking at the event entries in Splunk they are not showing any data:

alt text

When looking inside the forwarded Events everything looks as it should, only what is displayed in Splunk is wrong.
Help really appreciated!

Thanks and Regards

One additional question: The forwarded events are stored in a event file. Are they also stored within the SQL DB which Logbinder creates? Only relying on this file seems a bit crazy to me? How is Splunk crawling this file?

Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...