Splunk Search

Why are application logs not getting indexed in Splunk?

amand
New Member

The internal logs flow to splunk UI but the applications logs are not flowing to splunk UI.

We have a cluster with several different components. We are facing the above issue with only one of the component, although, the splunk configuration for all the components are same except the host differs.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @amand,

could you better describe your issue?

are you speking of one specific server or the issue is on all servers.

if on a specific server, which role has this server?

could you better describe your architecture? have you clusters?

Ciao.

Giuseppe

0 Karma

amand
New Member

We have 3 components in our cluster, assume A, B, C.
All have been configured in the same manner.
But we see application logs for B & C but not for A.
Although, we are able to see _internal index logs for A.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @amand,

I suppose that you're speaking of an Indexer Cluster and you distributed an add-on using the Master Node to all the peers.

Which are the application logs you're speaking of?

which is the add-on you're using?

Ciao.

Giuseppe

 

0 Karma

amand
New Member

We are able to see this on UI : index=_internal host=ip-xx-xx-xx-xxx source="/opt/splunkforwarder/var/log/splunk/splunkd.log"

 

but not this : index="blitz-athena" host=ip-xx-xx-xx-xxx                                                                                                           source = "/var/log/supervisord/collector.log"

 

P.S  : These two indexes are of the same host

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @amand,

can you see other events on the same index?

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...