<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Empty index after deployment of application in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196983#M39137</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;Here is quickly the situation: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;We have qualys_app on the Search Head with our dashboard.&lt;/LI&gt;
&lt;LI&gt;We have qualys_inputs on the Indexer with inputs.conf monitoring /tmp/qualys folder (we upload manually our files directly on the indexer)&lt;/LI&gt;
&lt;LI&gt;We have all_indexes application with indexes.conf with our config for our index (qualys).&lt;/LI&gt;
&lt;LI&gt;All apps are pushed by our deployment-server.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;When we upload our new .csv files by putting them into our folder /tmp/qualys, they are well indexed by the Indexer and our Dashboard show us what we want.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Our issue is&lt;/STRONG&gt;: when on the deployment-server we run ./splunk reload deploy-server&lt;BR /&gt;
After the reboot of the Indexer the index qualys is empty. So we loose our data previously indexed.&lt;/P&gt;

&lt;P&gt;My tests:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I suppose the problem can only comes from the Indexer and the apps deployed on the Indexer.&lt;/LI&gt;
&lt;LI&gt;I tried to see if there is another indexes.conf in the other deployed apps that might override the configuration.&lt;/LI&gt;
&lt;LI&gt;There is no errors in splunkd.log&lt;/LI&gt;
&lt;LI&gt;I re-import my data, so they have been re-indexed and then after a new deployment =&amp;gt; Empty index again.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;So I'm open to any suggestion.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Mar 2014 22:23:56 GMT</pubDate>
    <dc:creator>bgaignon</dc:creator>
    <dc:date>2014-03-20T22:23:56Z</dc:date>
    <item>
      <title>Empty index after deployment of application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196983#M39137</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;Here is quickly the situation: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;We have qualys_app on the Search Head with our dashboard.&lt;/LI&gt;
&lt;LI&gt;We have qualys_inputs on the Indexer with inputs.conf monitoring /tmp/qualys folder (we upload manually our files directly on the indexer)&lt;/LI&gt;
&lt;LI&gt;We have all_indexes application with indexes.conf with our config for our index (qualys).&lt;/LI&gt;
&lt;LI&gt;All apps are pushed by our deployment-server.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;When we upload our new .csv files by putting them into our folder /tmp/qualys, they are well indexed by the Indexer and our Dashboard show us what we want.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Our issue is&lt;/STRONG&gt;: when on the deployment-server we run ./splunk reload deploy-server&lt;BR /&gt;
After the reboot of the Indexer the index qualys is empty. So we loose our data previously indexed.&lt;/P&gt;

&lt;P&gt;My tests:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I suppose the problem can only comes from the Indexer and the apps deployed on the Indexer.&lt;/LI&gt;
&lt;LI&gt;I tried to see if there is another indexes.conf in the other deployed apps that might override the configuration.&lt;/LI&gt;
&lt;LI&gt;There is no errors in splunkd.log&lt;/LI&gt;
&lt;LI&gt;I re-import my data, so they have been re-indexed and then after a new deployment =&amp;gt; Empty index again.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;So I'm open to any suggestion.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 22:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196983#M39137</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-03-20T22:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Empty index after deployment of application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196984#M39138</link>
      <description>&lt;P&gt;Can you clarify the "index is empty"? Exactly what command are you executing to determine the index is empty? &lt;/P&gt;

&lt;P&gt;Once its indexed, unless the index on disk is being blown away somehow, you should not lose any data. However, if you are using a lookuptable, thats another story.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 21:40:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196984#M39138</guid>
      <dc:creator>gregbujak</dc:creator>
      <dc:date>2014-03-24T21:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Empty index after deployment of application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196985#M39139</link>
      <description>&lt;P&gt;Thanks Greg,&lt;/P&gt;

&lt;P&gt;The problem happened recently, I just capture an interesting log and based on the result I think the problem comes from:&lt;BR /&gt;
    [volume:primary]&lt;BR /&gt;
    path = /index&lt;BR /&gt;
    maxVolumeDataSizeMB = 5000&lt;/P&gt;

&lt;P&gt;maxVolumeDataSizeMB = 5000&lt;BR /&gt;
I put the size of my volume and reload the app.&lt;BR /&gt;
I 'll gave a feedback if it's solve the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 22:18:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196985#M39139</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-03-24T22:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Empty index after deployment of application</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196986#M39140</link>
      <description>&lt;P&gt;OK that was really stupid:&lt;BR /&gt;
The parameter in indexes.conf: maxVolumeDataSizeMB for the entire volume was as big as the size of 1 index.&lt;/P&gt;

&lt;P&gt;So that triggered the rolling data to frozen.&lt;BR /&gt;
Now fixed.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 13:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-index-after-deployment-of-application/m-p/196986#M39140</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-03-25T13:45:03Z</dc:date>
    </item>
  </channel>
</rss>

