Anything you need, any questions or concerns you have, you can ask us here. An NPB team member will get back to you promptly.

Can you provide the content of outputs.conf from your Heavy Forwarder? After enabling receiving on Forwarder, you would configure your forwarder to send data to those indexers on port 9997.

If I enable a Data Input to listen to port 9997, I can see data showing up in the index, albeit cooked data, which isn't readable - so the data is making it to the Splunk server, but just not showing up when I configure it to receive from another Splunk.

Image

Image

Image

I'm not really sure how to receive from a forwarder over Splunk web, but if you go into inputs.conf you can make sure you're receiving over splunktcp. If not, you can change it to Splunktcp.

When I enable receiving on the indexers (via Settings -> Forwarding and Receiving -> Configure Receiving), no data is showing up.