<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Installed Splunk but no Data! in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102346#M9535</link>
    <description>&lt;P&gt;mmm after doing what you advised "index=_internal" all seemed to work or it may have been a coincidence.&lt;/P&gt;

&lt;P&gt;regardless thank you for your help&lt;/P&gt;</description>
    <pubDate>Fri, 10 Dec 2010 07:13:32 GMT</pubDate>
    <dc:creator>canton</dc:creator>
    <dc:date>2010-12-10T07:13:32Z</dc:date>
    <item>
      <title>Installed Splunk but no Data!</title>
      <link>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102344#M9533</link>
      <description>&lt;P&gt;I have installed Splunk on server and can login to splunk and browse but no data is showing in search section waht so ever.&lt;/P&gt;

&lt;P&gt;I have also configured via &lt;STRONG&gt;Manager » Data inputs » Files &amp;amp; Directories&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;But still no luck what could be wrong?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2010 01:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102344#M9533</guid>
      <dc:creator>canton</dc:creator>
      <dc:date>2010-12-10T01:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Installed Splunk but no Data!</title>
      <link>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102345#M9534</link>
      <description>&lt;P&gt;So, when you go to &lt;EM&gt;Manager » Data inputs » Files &amp;amp; Directories&lt;/EM&gt; do you see the file/directory you added as listed? And does it show a number of files next to it?&lt;/P&gt;

&lt;P&gt;Is this directory perhaps owned by a different user and the splunk service does not have appropriate permissions to monitor/read the files within?&lt;/P&gt;

&lt;P&gt;Are you searching using the "all time" time-range? Perhaps this is historic data and not showing up in the timeframe you are searching?&lt;/P&gt;

&lt;P&gt;Lastly, if you search for &lt;CODE&gt;"index=_internal"&lt;/CODE&gt;, do you see any data show up?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2010 02:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102345#M9534</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-12-10T02:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Installed Splunk but no Data!</title>
      <link>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102346#M9535</link>
      <description>&lt;P&gt;mmm after doing what you advised "index=_internal" all seemed to work or it may have been a coincidence.&lt;/P&gt;

&lt;P&gt;regardless thank you for your help&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2010 07:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102346#M9535</guid>
      <dc:creator>canton</dc:creator>
      <dc:date>2010-12-10T07:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Installed Splunk but no Data!</title>
      <link>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102347#M9536</link>
      <description>&lt;P&gt;well, no, you have to be careful here. This means that you are receiving internal data. What about your OTHER data. Are you receiving the logs from the files that you already included in your data inputs?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2010 08:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installed-Splunk-but-no-Data/m-p/102347#M9536</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-12-10T08:52:56Z</dc:date>
    </item>
  </channel>
</rss>

