<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the new index not searchable? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400644#M14461</link>
    <description>&lt;P&gt;Wow. I was about to answer something like "If it was that easy...". But that's it. Can you tell me what the difference between "All-time (real time)" and "All time" is? I can see the logs only in "All time", which might be the reason why I couldn't see the obvious...&lt;/P&gt;

&lt;P&gt;But thanks for the tip!&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 06:54:06 GMT</pubDate>
    <dc:creator>AlteUnke</dc:creator>
    <dc:date>2018-08-14T06:54:06Z</dc:date>
    <item>
      <title>Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400639#M14456</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I'm new to Splunk and this is the first Index I created, so hopefully this Question ain't to nooby &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;This is my inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/app/retry.log]
disabled=false
sourcetype=log4j
index=retry
multiline_event_extra_waittime = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;indexes.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[retry]
homePath=$SPLUNK_DB/retry/db
coldPath=$SPLUNK_DB/retry/colddb
thawedPath=$SPLUNK_DB/retry/thaweddb
repFactor=autor        
maxDataSize=auto
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Cluster Bundle Status:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;master                        
         cluster_status=None                                                                         
         active_bundle             
                checksum=2924BEA962D9C72179B8CF4D03846EAB 
                timestamp=1533281547 (in localtime=Fri Aug  3 09:32:27 2018) 
         latest_bundle                                      
                checksum=2924BEA962D9C72179B8CF4D03846EAB                                                          
                timestamp=1533281547 (in localtime=Fri Aug  3 09:32:27 2018)                                      
         last_validated_bundle                                                                       
                checksum=2924BEA962D9C72179B8CF4D03846EAB                                                         
                last_validation_succeeded=1                                       
                timestamp=1533281547 (in localtime=Fri Aug  3 09:32:27 2018)                    
         last_check_restart_bundle   
                last_check_restart_result=restart not required  
                checksum=    
                timestamp=0 (in localtime=Thu Jan  1 01:00:00 1970)

 splunkidx2    3F5EEC11-8718-4C0D-AEF7-0F54DABB1D01    default                   
         active_bundle=2924BEA962D9C72179B8CF4D03846EAB                                               
         latest_bundle=2924BEA962D9C72179B8CF4D03846EAB                 
         last_validated_bundle=2924BEA962D9C72179B8CF4D03846EAB                                          
         last_bundle_validation_status=success                                     
         restart_required_apply_bundle=0        
         status=Up     

 splunkidx3    79FD9BAC-9F72-46CB-A043-EDCA31DE8EB7    default                           
         active_bundle=2924BEA962D9C72179B8CF4D03846EAB        
         latest_bundle=2924BEA962D9C72179B8CF4D03846EAB 
         last_validated_bundle=2924BEA962D9C72179B8CF4D03846EAB                   
         last_bundle_validation_status=success    
         restart_required_apply_bundle=0  
         status=Up

 splunkidx1    D2077BB4-988A-46F2-BB00-E261EBF94BC9    default               
         active_bundle=2924BEA962D9C72179B8CF4D03846EAB    
         latest_bundle=2924BEA962D9C72179B8CF4D03846EAB
         last_validated_bundle=2924BEA962D9C72179B8CF4D03846EAB                                               
         last_bundle_validation_status=success                     
         restart_required_apply_bundle=0                                                         
         status=Up
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I can see the new "retry" Index in Splunk and add it to roles. But I can't search for it, or find events when search for "index=retry".&lt;BR /&gt;
But I can see the rawdata/db on the Indexers, so Data is here.&lt;BR /&gt;
Any Idea what I could have missed? &lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 12:08:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400639#M14456</guid>
      <dc:creator>AlteUnke</dc:creator>
      <dc:date>2018-08-13T12:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400640#M14457</link>
      <description>&lt;P&gt;Hello, did you try expanding the time range for the results. Try searching for "All Time" (in time range picker) and see if any data shows up. &lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 13:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400640#M14457</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-13T13:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400641#M14458</link>
      <description>&lt;P&gt;Check the roles assigned to the new index if the current role you are using is allowed to see the data&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 16:19:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400641#M14458</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-08-13T16:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400642#M14459</link>
      <description>&lt;P&gt;Also, in your index definition, it should be "repFactor=auto", not "repFactor=autor"&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 17:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400642#M14459</guid>
      <dc:creator>Steve_G_</dc:creator>
      <dc:date>2018-08-13T17:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400643#M14460</link>
      <description>&lt;P&gt;Uh, thanks for that! Didn't see that!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 06:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400643#M14460</guid>
      <dc:creator>AlteUnke</dc:creator>
      <dc:date>2018-08-14T06:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400644#M14461</link>
      <description>&lt;P&gt;Wow. I was about to answer something like "If it was that easy...". But that's it. Can you tell me what the difference between "All-time (real time)" and "All time" is? I can see the logs only in "All time", which might be the reason why I couldn't see the obvious...&lt;/P&gt;

&lt;P&gt;But thanks for the tip!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 06:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400644#M14461</guid>
      <dc:creator>AlteUnke</dc:creator>
      <dc:date>2018-08-14T06:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400645#M14462</link>
      <description>&lt;P&gt;I believe my misunderstanding was, that I used logs which all had the date "03.08.2018". I just copy/pasted them, thinking splunk would log them under "last 7 days" depending on the time the log was added and not the date which is written in the log-entry.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 07:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400645#M14462</guid>
      <dc:creator>AlteUnke</dc:creator>
      <dc:date>2018-08-14T07:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400646#M14463</link>
      <description>&lt;P&gt;One thing i observed in indexes.conf is " repFactor = autor " which is invalid.&lt;/P&gt;

&lt;P&gt;Can you change to "repFactor = auto"  and try to push bundles again to peers.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Configurethepeerindexes#1._Edit_indexes.conf"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Indexer/Configurethepeerindexes#1._Edit_indexes.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 07:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400646#M14463</guid>
      <dc:creator>bpadmanbhachari</dc:creator>
      <dc:date>2018-08-14T07:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400647#M14464</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/7.0.3/Search/Aboutrealtimesearches"&gt;Real-time searches&lt;/A&gt; scan events as the events arrive for indexing. When you kick off a real-time search, Splunk software scans the incoming events. The scan looks for events that contain index-time fields that indicate the event could be a match for your search.&lt;/P&gt;

&lt;P&gt;"All-time (real-time)" search will continue running until you or another user stops the search or deletes the search job whereas "All-time" search stops once it has returned all the events matching the search criteria. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 13:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400647#M14464</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-14T13:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the new index not searchable?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400648#M14465</link>
      <description>&lt;P&gt;Splunk's default timestamp recognition process extracts timestamps found in the events unless instructed otherwise.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 13:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-new-index-not-searchable/m-p/400648#M14465</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-14T13:35:42Z</dc:date>
    </item>
  </channel>
</rss>

