Somerford Associates Limited·Follow3 min read·Feb 28, 2023--Author: Grace DolbyRelease Date: 15/11/2022Working with a large customer base and supporting their Splunk deployments has led us to understand the common issues or queries that many will have when deploying or administrating a Splunk instance day-to-day. Hopefully, this blog will allow you to be able to confidently investigate and resolve these issues whether you are running on-premise or cloud.1. Data not coming in from a Universal Forwarder or other data input typeThis issue is probably the most frustrating, because after all your hard work and configuration you go to look in your index in Splunk and alas, there are no events found! There may be multiple reasons for this, however, being able to use the internal logs to your advantage can narrow it down.Some things that you can check on your UF first:Can Splunk read the directory or file you want it to monitor?Are there communication issues between your UF and your Indexer?Yo...