<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot getting data into indexes in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660622#M17623</link>
    <description>&lt;P&gt;Thanks for the answer.&amp;nbsp; Everyting seems to be ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;disk not full, licenses ok, rebooted several times, restarted splunk several times. But still we don't receive&amp;nbsp; data into indexes.&amp;nbsp; To save time, I wondered if it's possible to backup some files $SPLUNK_HOME/etc, and then reinstall splunk sw +&amp;nbsp; copy files into new installation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think it will work?&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Geir&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 07:16:30 GMT</pubDate>
    <dc:creator>gjhaaland</dc:creator>
    <dc:date>2023-10-13T07:16:30Z</dc:date>
    <item>
      <title>Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660542#M17605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For some reason we cannot receive data to _interal or other indexes(all of them). Old indexes are still available through database. It looks like a generic problem, not related to any specific index. All I can see is _audit.&lt;/P&gt;&lt;P&gt;Maybe it's ok to backup $SPLUNK_HOME/etc, and then reinstall splunk sw? or if possible restart some processes, or modify config file. input, output.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Geir&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 15:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660542#M17605</guid>
      <dc:creator>gjhaaland</dc:creator>
      <dc:date>2023-10-12T15:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660546#M17606</link>
      <description>&lt;P&gt;What error messages do you see?&amp;nbsp; Are the indexes or the disk they're&amp;nbsp; on full?&lt;/P&gt;&lt;P&gt;Restarting or re-installing Splunk may help correct some causes of the problem, but not the most likely ones.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 15:52:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660546#M17606</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-12T15:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660622#M17623</link>
      <description>&lt;P&gt;Thanks for the answer.&amp;nbsp; Everyting seems to be ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;disk not full, licenses ok, rebooted several times, restarted splunk several times. But still we don't receive&amp;nbsp; data into indexes.&amp;nbsp; To save time, I wondered if it's possible to backup some files $SPLUNK_HOME/etc, and then reinstall splunk sw +&amp;nbsp; copy files into new installation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think it will work?&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Geir&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 07:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660622#M17623</guid>
      <dc:creator>gjhaaland</dc:creator>
      <dc:date>2023-10-13T07:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660636#M17624</link>
      <description>&lt;P&gt;Did you try btool to check your configs, indexes.conf , inputs etc. may be there is a overlapping setting routing data somewhere else.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 10:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660636#M17624</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2023-10-13T10:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660637#M17625</link>
      <description>&lt;P&gt;or you are getting any permissions issue on splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 10:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660637#M17625</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2023-10-13T10:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660641#M17628</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; No problems with persmissions.&amp;nbsp; It could be something wrong with with some confiles.&amp;nbsp; But since the proplems&amp;nbsp; involves all indexfiles it must be something global settings, or some services/program not running.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you thinks it's best to backup $SPLUNK/etc, run installation/upgrade and next copy etc files into new installation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Geir&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 10:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660641#M17628</guid>
      <dc:creator>gjhaaland</dc:creator>
      <dc:date>2023-10-13T10:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660643#M17629</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If you cannot get any new data then mos obvious reason is that you have that disk space full. Second one is that for some reason your permissions / ownerships have changed on disk.&lt;/P&gt;&lt;P&gt;Please try "source /opt/splunk/bin/setSplunkEnv &amp;amp;&amp;amp; df -H $SPLUNK_HOME $SPLUNK_DB" as a root on cmd line. Also check if you have volumes in use and check that disk space also.&lt;/P&gt;&lt;P&gt;To find volumes you should login as splunk user and then use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool indexes list volume|egrep '(\[|path)'&lt;/LI-CODE&gt;&lt;P&gt;Which show those physical disk areas what those are using.&lt;/P&gt;&lt;P&gt;If there are enough space left then you should check ownership of those directories / files and change those if needed.&lt;/P&gt;&lt;P&gt;Did I understand right that you get some new data into _audit index, but not anywhere else?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 10:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660643#M17629</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-10-13T10:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot getting data into indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660646#M17631</link>
      <description>&lt;P&gt;No problems with permissions, diskusage ++. I think it's a global problems. I know that for some days ago I tried to setup pkcs12 certificate (estreamer)&amp;nbsp; on splunk server.&amp;nbsp; &amp;nbsp;But can't remember where I did these settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out form commands:&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ source /home/splunk/bin/setSplunkEnv &amp;amp;&amp;amp; df -H $SPLUNK_HOME $splunk_db&lt;BR /&gt;Tab-completion of "splunk &amp;lt;verb&amp;gt; &amp;lt;object&amp;gt;" is available.&lt;BR /&gt;Filesystem Size Used Avail Use% Mounted on&lt;BR /&gt;/dev/mapper/centos-home 886G 587G 300G 67% /home&lt;BR /&gt;$&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;$sudo /home/splunk/bin/splunk btool indexes list volume |egrep '(\[|path)'&lt;BR /&gt;[volume:_splunk_summaries]&lt;BR /&gt;path = $SPLUNK_DB&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;$df&lt;BR /&gt;Filesystem 1K-blocks Used Available Use% Mounted on&lt;BR /&gt;/dev/mapper/centos-root 52403200 11477568 40925632 22% /&lt;BR /&gt;devtmpfs 16312676 0 16312676 0% /dev&lt;BR /&gt;tmpfs 16329816 0 16329816 0% /dev/shm&lt;BR /&gt;tmpfs 16329816 10560 16319256 1% /run&lt;BR /&gt;tmpfs 16329816 0 16329816 0% /sys/fs/cgroup&lt;BR /&gt;/dev/sda3 1038336 173348 864988 17% /boot&lt;BR /&gt;/dev/mapper/centos-home 865131800 558906488 306225312 65% /home&lt;BR /&gt;tmpfs 3265964 12 3265952 1% /run/user/42&lt;BR /&gt;tmpfs 3265964 0 3265964 0% /run/user/1001&lt;BR /&gt;$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 11:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-getting-data-into-indexes/m-p/660646#M17631</guid>
      <dc:creator>gjhaaland</dc:creator>
      <dc:date>2023-10-13T11:01:05Z</dc:date>
    </item>
  </channel>
</rss>

