Splunk Search

Why is splunk not showing logs when searched with index?

sindhuja
Loves-to-Learn Lots

Hi All,

 

I have integrated Splunk HEC with springboot .when i hit application and checked in splunk am unable to see logs in splunk search with given index .am using source type as log4j2 

Can any one help me .

 

Thanks in advance

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sindhuja,

as @yuanliu said, it seems to be an ingestion problem, but to me more sure, you could use a larger search:

index=* sourcetype=log4j

and see results.

Then you could analyze the input phase to identify where's the problem.

Ciao.

Giuseppe

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Looks like an ingestion problem, not a search problem.  You'll get better information by moving this to Getting Data In.  Do you have any log indicating that HEC ingestion happened?

0 Karma

sindhuja
Loves-to-Learn Lots

hi @yuanliu

 

How can i check HEC ingestion happened from my application side?

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

I can only say to review logs on both the sender side and splunkd.log.  My only experience with HEC is from Puppet's Splunk HEC app, and the only thing I had to figure out was how to force HEC to offer outdated SSL algorithm. (Not the app's fault, just to be clear.)  It is hard to read error messages that don't tell you how to solve.  But no error message would make it much harder - and absence of error remains a possibility.  That's why I suggested Admin forum.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...