<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexed Data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexed-Data/m-p/685358#M114345</link>
    <description>&lt;P&gt;I made my configuration for inputs.conf to ingest data into splunk but not getting data, during my investigation to check if there is any issue i realize the configured source is not showing any data and i cant see the source path in the index in splunk. Is there a reason why am not seeing the source after configuring the inputs.conf&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 17:18:21 GMT</pubDate>
    <dc:creator>whitecat001</dc:creator>
    <dc:date>2024-04-24T17:18:21Z</dc:date>
    <item>
      <title>Indexed Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexed-Data/m-p/685358#M114345</link>
      <description>&lt;P&gt;I made my configuration for inputs.conf to ingest data into splunk but not getting data, during my investigation to check if there is any issue i realize the configured source is not showing any data and i cant see the source path in the index in splunk. Is there a reason why am not seeing the source after configuring the inputs.conf&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 17:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexed-Data/m-p/685358#M114345</guid>
      <dc:creator>whitecat001</dc:creator>
      <dc:date>2024-04-24T17:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Indexed Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexed-Data/m-p/685359#M114346</link>
      <description>&lt;P&gt;It could be a n umber of things as to why the data is not coming through or not showing.&lt;BR /&gt;&lt;BR /&gt;1.Whatever your monitoring does it have read permissions?&lt;BR /&gt;2.Check for typos' (index name etc)&lt;/P&gt;&lt;P&gt;You can also check the internal logs for clues&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd host=neo log_level=INFO component=WatchedFile 
| table host, _time, component, event_message, log_level
| sort - _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the output of this command - it shows whats being monitored (Assuming its a linux host)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk list inputstatus&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you able to show us your inputs.conf and describe what you are trying to monitor?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 17:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexed-Data/m-p/685359#M114346</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-04-24T17:35:52Z</dc:date>
    </item>
  </channel>
</rss>

