<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk is not indexing anymore in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759417#M120363</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a little more info on how you are receiving this data into Splunk?&lt;/P&gt;&lt;P&gt;When you look at&amp;nbsp;&lt;A href="https://yoursplunkinstance/en-US/manager/bowl/data/indexes" target="_blank"&gt;https://yoursplunkinstance/en-US/manager/bowl/data/indexes&lt;/A&gt;&amp;nbsp;do you see the index that you are expecting to see logs for? When does it say the most recent event is from?&lt;/P&gt;&lt;P&gt;Can you check Splunk is listening on the relevant port (e.g. can you netcat to it or see it open in some other way?)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2026 21:08:14 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2026-03-18T21:08:14Z</dc:date>
    <item>
      <title>Splunk is not indexing anymore</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759409#M120360</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I hope you are doing well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently i am going through a critical issue on my splunk entreprise. I used to receive logs from switches and firewalls and everything was fine.&lt;/P&gt;&lt;P&gt;Until yesterday, splunk stopped indexing everything, at first i thought the firewalls stopped sending logs , but it was not the case , i even launched the tcpdump command on the VM hosting splunk , and i see that the logs arrives , but when i search on splunk , i cannot find anything.&lt;/P&gt;&lt;P&gt;If you have any idea please or you could suggest any ideas , I would appreciate your help.&lt;/P&gt;&lt;P&gt;I m using splunk entrprise 10.0.0 hosted on ubuntu 22.04. Also i do not have any shortage when it comes to resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 15:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759409#M120360</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-03-18T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not indexing anymore</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759411#M120361</link>
      <description>&lt;P&gt;It's very hard to tell with such limited info.&lt;/P&gt;&lt;P&gt;1. Check if all your components are up and running.&lt;/P&gt;&lt;P&gt;2. If you're saying that "logs arrive", since you're talking about network equipment, do you mean that you see just UDP frames or TCP streams? Remember that UDP can appear on the wire but still not get delivered to the process even if the process is listening. Any changes on the boxes network-wise? Someone fiddled with the local firewall rules?&lt;/P&gt;&lt;P&gt;3. Is Splunk indexing _any_ data? Do you have only problem with the network equipment logs or everything (including Splunk's _internal)?&lt;/P&gt;&lt;P&gt;4. How did you verify that it stopped indexing? Maybe something changed regarding time settings - that could cause Splunk to parse time wrongly and index it into wrong point in time (effectively not showing it when you're searching for "last 15 minutes" or similar). Try running an All Time (realtime) search across your indexes and look if anything shows up. (that's pretty much the only case I'd advise anyone to run a realtime search).&lt;/P&gt;&lt;P&gt;5. Did you check indexes metadata (both on Monitoring Console level as well as physically on bucket directories)?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 16:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759411#M120361</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-03-18T16:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not indexing anymore</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759417#M120363</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a little more info on how you are receiving this data into Splunk?&lt;/P&gt;&lt;P&gt;When you look at&amp;nbsp;&lt;A href="https://yoursplunkinstance/en-US/manager/bowl/data/indexes" target="_blank"&gt;https://yoursplunkinstance/en-US/manager/bowl/data/indexes&lt;/A&gt;&amp;nbsp;do you see the index that you are expecting to see logs for? When does it say the most recent event is from?&lt;/P&gt;&lt;P&gt;Can you check Splunk is listening on the relevant port (e.g. can you netcat to it or see it open in some other way?)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 21:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759417#M120363</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-03-18T21:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not indexing anymore</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759534#M120374</link>
      <description>Are you sure that splunk has stopped to indexing or is it stopped to answer your queries? The 2nd option is more possible than 1st one!&lt;BR /&gt;So how you have made conclusion that it has stopped ingestion?</description>
      <pubDate>Fri, 20 Mar 2026 22:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759534#M120374</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-03-20T22:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is not indexing anymore</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759538#M120376</link>
      <description>&lt;P&gt;Hello Team ,&lt;/P&gt;&lt;P&gt;Thank you all for your replies. Actually after deep investigations it turned out it was a mistake made by one of our team.&lt;/P&gt;&lt;P&gt;To put you in the context, we have had an issue in Splunk , the Forwarder agents won't show up in the agent mangement section, son one of the Team looked this up and found a similar case and it was resolved by adding those lines on outputs.conf :&amp;nbsp;&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;/P&gt;&lt;P&gt;index = true&lt;/P&gt;&lt;P&gt;selectiveIndexing = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and this the issue all indexes stopped indexing. by removing those lines everything got back to work noemally.&lt;/P&gt;&lt;P&gt;Thank you again for you help.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2026 12:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-not-indexing-anymore/m-p/759538#M120376</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-03-21T12:38:25Z</dc:date>
    </item>
  </channel>
</rss>

