<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: index=main not working in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/712837#M21739</link>
    <description>Have you activated eventgen's inputs on Splunk side?</description>
    <pubDate>Fri, 28 Feb 2025 15:32:59 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-02-28T15:32:59Z</dc:date>
    <item>
      <title>index=main not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/711944#M21682</link>
      <description>&lt;P&gt;Hello! I hope you can help! I have installed splunk enterprise 8.12 on my MAC OS 14.6.1 to study for an exam. Splunk installed fine. However the lab asked me to create an app called "destinations" which i did and i set the proper permissions. However, when i go to the app in the search head and type "index=main" it sees it but doesn't display any records. I have copied down eventgen to the samples folder in Destinations&amp;nbsp; folder in the samples folder and copied the eventgen.conf to the local folder as directed but it still does not display.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also see that the main index is enabled in indexes using theb $SPLUNK_DB/defaultdb/db&amp;nbsp;&lt;/P&gt;&lt;P&gt;it also shows that it indexed 1mg out of 500gb.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a feeling that its something obvious but im not seeing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really need this lab to work can you assist?&amp;nbsp; I used SPLK-10012.PDF instructions. not sure if you have access to that. i pulled down the files fro github&amp;nbsp; -&amp;nbsp;&lt;SPAN&gt;eventgen&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Maybe this is an easy fix?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 18:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/711944#M21682</guid>
      <dc:creator>aschampion</dc:creator>
      <dc:date>2025-02-18T18:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: index=main not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/712757#M21732</link>
      <description>&lt;P&gt;Hello, is it solved? Did you check splunkd.log for warnings/errors?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 22:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/712757#M21732</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2025-02-27T22:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: index=main not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/712837#M21739</link>
      <description>Have you activated eventgen's inputs on Splunk side?</description>
      <pubDate>Fri, 28 Feb 2025 15:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-main-not-working/m-p/712837#M21739</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-02-28T15:32:59Z</dc:date>
    </item>
  </channel>
</rss>

