Hi,
I have installed Splunk Enterprise version locally and configured the below from Splunk Web.
1-forwarding host:port, (localhost:9997)
2-receiving port to match with the same port.(9997)
3- Data input to point to a directory (c:\data)
I don't see any data in search and reporting, even on adding files to the directory (c:\data)
Can I not use the same local instance as both a forwarder and indexer?
Thanks,
Saravana
↧