Hi,
I setup a forwarder on a linux server and setup Splunk to listen on port 9997 and I added the index name (cisco) I previously setup into the inputs.conf file.
On the Splunk indexer, if I search "index=cisco", I can see all my data.
However, my "Search" page is not displaying any "Hosts", any "Sources" and any "SourceTypes"....whereas I am receiving all data.
Any idea what is wrong ?
Philippe
... View more