Getting Data In

How can I transfer logs of a sever to an indexer?

Utkarsh_Singh
New Member

I have created an index A for server X and I have done all the required setting in the inputs.conf file of server X. I have checked that logs are monitored by Splunk through "Splunk list monitor" command but logs are not reaching to index.
What can be done?

Tags (2)
0 Karma

felipesewaybric
Contributor

now you need to config your output.conf

first use this in your UF:

./splunk list forward-server
then
./splunk add forward-server :

and check if the port is open in your server

0 Karma

Utkarsh_Singh
New Member

Ports are open i have checked already

0 Karma

micahkemp
Champion

inputs.conf is only part of the solution. This documentation page steps you through enabling the receiver on the indexer and adding a forward server on the forwarder.

0 Karma

Utkarsh_Singh
New Member

i have done all the configuration still i am on same page.

0 Karma

felipesewaybric
Contributor

i know it sounds dumb, but did you restart your forwarder? It appears as active with this command?
./splunk list forward-server

0 Karma

micahkemp
Champion

Please share your

indexes.conf on the indexer
inputs.conf on the indexer

inputs.conf on the forwarder
props.conf on the forwarder
outputs.conf on the forwarder

that you have put in place for this task.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...