<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is splunk not indexing all the data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303226#M57271</link>
    <description>&lt;P&gt;Try running following on your forwarder instance. See if Splunk is monitoring all the files you've configured for monitoring (will prompt for admin credentials for that Splunk instance)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 21 Feb 2018 19:08:07 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2018-02-21T19:08:07Z</dc:date>
    <item>
      <title>Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303222#M57267</link>
      <description>&lt;P&gt;Hi, lately we've been checking how many files our splunk is indexing, and we noticed that it "skips" some files... We checked by searching:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=our_index | stats dc(source)
index = _internal group = per_so* series=*.ourfile | stats count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And both ways we got the same results, which are not all the files we indexed.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 16:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303222#M57267</guid>
      <dc:creator>eylonronen</dc:creator>
      <dc:date>2018-02-21T16:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303223#M57268</link>
      <description>&lt;P&gt;A cheerful place to start at &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 16:55:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303223#M57268</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-02-21T16:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303224#M57269</link>
      <description>&lt;P&gt;Also, check internal logs from yoru forwarder(s) to see if there are any warnings/error for your files. ( &lt;CODE&gt;index=_itnernal sourcetype=splunkd host=yourFwd *filename.ext*&lt;/CODE&gt; )&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 17:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303224#M57269</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-21T17:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303225#M57270</link>
      <description>&lt;P&gt;I've already looked there... Zero warnings or errors....&lt;BR /&gt;
Also we've tried both monitor and batch input. Both had the same problem...&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 18:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303225#M57270</guid>
      <dc:creator>eylonronen</dc:creator>
      <dc:date>2018-02-21T18:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303226#M57271</link>
      <description>&lt;P&gt;Try running following on your forwarder instance. See if Splunk is monitoring all the files you've configured for monitoring (will prompt for admin credentials for that Splunk instance)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Feb 2018 19:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303226#M57271</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-21T19:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303227#M57272</link>
      <description>&lt;P&gt;Even if there are no errors/warnings, do you see any entry for your log file that's missing?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd host=yourFwd  adding watch
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Feb 2018 19:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303227#M57272</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-21T19:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303228#M57273</link>
      <description>&lt;P&gt;well the forwarder doesnt write log when it monitors, only with batch input for some reason. Today we indexed some logs, and we saw one of the files in the forwarders log, but we could not search it...&lt;BR /&gt;
I wonder if it has something to do with the fact that we added a few indexers recently.&lt;BR /&gt;
Is there something i should update in the search head when i add indexers?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 19:17:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303228#M57273</guid>
      <dc:creator>eylonronen</dc:creator>
      <dc:date>2018-02-21T19:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not indexing all the data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303229#M57274</link>
      <description>&lt;P&gt;I didn't find any help in this page....&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 06:19:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-splunk-not-indexing-all-the-data/m-p/303229#M57274</guid>
      <dc:creator>eylonronen</dc:creator>
      <dc:date>2018-02-22T06:19:49Z</dc:date>
    </item>
  </channel>
</rss>

