Splunk Enterprise

Splunk app for Logbinder - Event Entries empty

juerchri
New Member

Hi guys,

I installed Supercharger, Splunk and Splunk app for Logbinder in order to configure log forwarders and have them visualized within Splunk (like here https://support.logbinder.com/SuperchargerKB/50135/8-Install-Supercharger-with-Splunk-Light-and-the-...)
So far everything worked flawless, Events are forwarded and collected but when looking at the event entries in Splunk they are not showing any data:

alt text

When looking inside the forwarded Events everything looks as it should, only what is displayed in Splunk is wrong.
Help really appreciated!

Thanks and Regards

One additional question: The forwarded events are stored in a event file. Are they also stored within the SQL DB which Logbinder creates? Only relying on this file seems a bit crazy to me? How is Splunk crawling this file?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...