Help regarding Troubleshooting log i.e if unable to find the reason of not getting my logs..
Look carefully through the output of the following commands (assuming Linux, and you have splunk
in your path, etc.):
splunk list monitor | less
splunk btool inputs list --debug | less
splunk btool inputs list --debug | less
It would help if you provide a bit more context. What kind of data, how are you collecting it, what does your architecture look like etc.
One thing you may want to check is whether timestamping is happening correctly, so make sure to search over "all time" to make sure you don't mis events that are wrongly timestamped.