I have a forwarder and an indexer.
I see the app is deployed in the forwarder at location etc/apps/.
Forwarders are up and running.
And log files have data as well.
But still the logs are not coming up on the Splunk search head.
- props.conf is correct
- inputs.conf is correct
Please guide, where else can I check and how to troubleshoot?
↧