<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data is not making to indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82127#M16962</link>
    <description>&lt;P&gt;I'm unable to index the data on the same splunk instance even. My inputs.conf file on the same instance. I can't see any testindex being created.&lt;BR /&gt;
[default]&lt;BR /&gt;
host = vm10177&lt;BR /&gt;
[monitor:///home/ssanke/SplunkTests/logs/DistSearch]&lt;BR /&gt;
index = testindex&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2012 19:44:46 GMT</pubDate>
    <dc:creator>ssankeneni</dc:creator>
    <dc:date>2012-10-05T19:44:46Z</dc:date>
    <item>
      <title>Data is not making to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82125#M16960</link>
      <description>&lt;P&gt;The Data forwarded by universal forwarder is not making to the indexer. There is no clue on splunkd.log file even. It shows that the forwarder has made a connection to indexer. Any help would be appreciated. &lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 19:28:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82125#M16960</guid>
      <dc:creator>ssankeneni</dc:creator>
      <dc:date>2012-10-05T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not making to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82126#M16961</link>
      <description>&lt;P&gt;Please provide much more details on your setup - inputs, outputs, etc etc. It's impossible to help you without having any details.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 19:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82126#M16961</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-05T19:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not making to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82127#M16962</link>
      <description>&lt;P&gt;I'm unable to index the data on the same splunk instance even. My inputs.conf file on the same instance. I can't see any testindex being created.&lt;BR /&gt;
[default]&lt;BR /&gt;
host = vm10177&lt;BR /&gt;
[monitor:///home/ssanke/SplunkTests/logs/DistSearch]&lt;BR /&gt;
index = testindex&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 19:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82127#M16962</guid>
      <dc:creator>ssankeneni</dc:creator>
      <dc:date>2012-10-05T19:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not making to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82128#M16963</link>
      <description>&lt;P&gt;First, you must create the index before you direct any inputs to the index. Go to &lt;STRONG&gt;Manager&amp;gt;&amp;gt;Indexes&lt;/STRONG&gt; and create the &lt;CODE&gt;testindex&lt;/CODE&gt; there.&lt;/P&gt;

&lt;P&gt;Second, searches only include a default set of indexes, based on your role. When you create a new index (such as &lt;CODE&gt;textindex&lt;/CODE&gt;), you need to add it to any roles where you wish for the new index to be searched by default. You also must include the new index in any roles that will be allowed to search it explicitly. Go to &lt;STRONG&gt;Manager&amp;gt;&amp;gt;Access Controls&lt;/STRONG&gt; to edit these settings.&lt;/P&gt;

&lt;P&gt;If  you did create the &lt;CODE&gt;testindex&lt;/CODE&gt;, try this search to see if there is anything in it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=testindex
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can also look at the &lt;CODE&gt;testindex&lt;/CODE&gt; in &lt;STRONG&gt;Manager&amp;gt;&amp;gt;Indexes&lt;/STRONG&gt;, which will show how many events it contains.&lt;/P&gt;

&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 23:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82128#M16963</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-10-05T23:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not making to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82129#M16964</link>
      <description>&lt;P&gt;Thanks for the answer.. but my problem was the indexer is forwarding to another server. I removed it and it started working back. Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 18:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-making-to-indexer/m-p/82129#M16964</guid>
      <dc:creator>ssankeneni</dc:creator>
      <dc:date>2012-10-09T18:10:40Z</dc:date>
    </item>
  </channel>
</rss>

