Hi Group,
I am new to the Splunk thing so bear with me.
I have installed an indexer, configured it to look at some local log files and that seems to work ok. I have also installed a forwarder on another machine and configure it to monitor a file and connect to the Indexer. As far as I can tell the file is being monitored and the data is sent to the Indexer and being indexed – at least I can see the index having count and size_bytes if I look under “Status –> Index activity -> Index activity overview”.
The problem is that if I look on the search page I can only see one source – namely the local file. My searches do not show any entries form the file on the indexer. Additionally – and this I find very strange – if under “Status –> Index activity -> Index activity overview” I drill down into the index for the remote server it shows me the entries from the local file on the indexer.
(Splunk 4.2 on Solaris 10 X86)
Thanks
... View more