Quantcast
Viewing all articles
Browse latest Browse all 47296

I have a forwarder and indexer set up, but why am I unable to search logs from the search head?

I have a forwarder and an indexer. I see the app is deployed in the forwarder at location etc/apps/. Forwarders are up and running. And log files have data as well. But still the logs are not coming up on the Splunk search head. - props.conf is correct - inputs.conf is correct Please guide, where else can I check and how to troubleshoot?

Viewing all articles
Browse latest Browse all 47296

Trending Articles