<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events from new index are not showing up in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79919#M181781</link>
    <description>&lt;P&gt;All that I had to do was restart the individual indexers, which the heavy forwarder was reporting to.  After doing this, events began showing up in the search.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2012 17:27:41 GMT</pubDate>
    <dc:creator>kjohnsonzenimax</dc:creator>
    <dc:date>2012-10-10T17:27:41Z</dc:date>
    <item>
      <title>Events from new index are not showing up</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79916#M181778</link>
      <description>&lt;P&gt;I have inherited a fairly undocumented splunk deployment which looks as follows (splunk 4.3.2):&lt;/P&gt;

&lt;P&gt;Forwarders -&amp;gt; 2x Heavy Forwarders -&amp;gt; 3x Indexers -&amp;gt; Search Head&lt;/P&gt;

&lt;P&gt;I have added an index to the Search Head via the web interface and installed two forwarders with an inputs.conf as below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:////opt/tld/glassfish/domains/tldcs/logs/feedback.log]
sourcetype = tld_gameplay
index = tld_gameplay

[monitor:////home/tldcs/web/apps/cstools/log/production.log]
index = customer_service

[monitor:////opt/tld/glassfish/domains/tldcs/logs/server.log]
index = customer_service

[monitor:////opt/tld/glassfish/domains/tldcs/logs/services.log]
index = customer_service
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The issue is that I am not seeing any events in the web interface.&lt;BR /&gt;&lt;BR /&gt;
How can I debug this?  What information do you need from me, so that I can help you?  How can I verify that data is, or is not, even being received by the heavy forwarder, and then the indexers?&lt;/P&gt;

&lt;P&gt;I am unclear whether I need to "add" the index somewhere else other than via the web interface.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2012 12:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79916#M181778</guid>
      <dc:creator>kjohnsonzenimax</dc:creator>
      <dc:date>2012-10-04T12:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Events from new index are not showing up</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79917#M181779</link>
      <description>&lt;P&gt;Adding the index on the web interface adds it to the search head's local filesystem. It doesn't add it on the indexers themselves. In a lot of cases, the web interface of the indexers is turned off, to save memory as it commonly isn't used in this kind of distributed environment. I'd suggest first going to the indexers (command line is OK) and issuing &lt;CODE&gt;splunk list indexes&lt;/CODE&gt; to see if your indexers have this new one.&lt;/P&gt;

&lt;P&gt;You could then add them directly to the indexes.conf, or temporarily spin up the Splunk UI on the indexers to be able to use the UI to add the index.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2012 20:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79917#M181779</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-10-04T20:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Events from new index are not showing up</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79918#M181780</link>
      <description>&lt;P&gt;Hey, thanks for your answer.  I have just checked the three indexers, running the command 'splunk list index' and have verified that the new index is listed on all three indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 17:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79918#M181780</guid>
      <dc:creator>kjohnsonzenimax</dc:creator>
      <dc:date>2012-10-10T17:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Events from new index are not showing up</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79919#M181781</link>
      <description>&lt;P&gt;All that I had to do was restart the individual indexers, which the heavy forwarder was reporting to.  After doing this, events began showing up in the search.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 17:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-from-new-index-are-not-showing-up/m-p/79919#M181781</guid>
      <dc:creator>kjohnsonzenimax</dc:creator>
      <dc:date>2012-10-10T17:27:41Z</dc:date>
    </item>
  </channel>
</rss>

