Getting Data In

Active forwards: 10.20.30.40:9997 Configured but inactive forwards: None

rahul2gupta
Path Finder

Hi,

When I ran the command ./splunk list forward-server , we are getting below error message.

Active forwards:
10.20.30.40:9997
Configured but inactive forwards:
None

Can you please help me to troubleshoot the below error?

Regards,

Rahul Gupta

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

What is your error? This said that you have configured one forwarder which are currently in use?

0 Karma

rahul2gupta
Path Finder

Hi @isoutamo ,

logs are not getting ingested into splunk.

Regards,

Rahul

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Is that a correct address for your indexer?

Did you see internal logs from that forwarder or other FWDs?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...