<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sourcetypes not loading any data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650827#M225023</link>
    <description>&lt;P&gt;data loaded when I put in that search. I don't understand how this relates to my problem though, how do I view the inputs I want?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 13:19:31 GMT</pubDate>
    <dc:creator>henryf</dc:creator>
    <dc:date>2023-07-17T13:19:31Z</dc:date>
    <item>
      <title>Why are my sourcetypes not loading any data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650615#M224934</link>
      <description>&lt;P&gt;I have installed Splunk add on for AWS and created the inputs, which have a listed source type. However, when I try to search that source type, nothing comes up for the source. How can I fix this?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 00:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650615#M224934</guid>
      <dc:creator>henryf</dc:creator>
      <dc:date>2023-07-18T00:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650622#M224939</link>
      <description>&lt;P&gt;Sourcetype is only one factor for finding indexed data.&amp;nbsp; You also must look in the right index(es) and in the right time window.&lt;/P&gt;&lt;P&gt;The AWS input should have specified an index name for the data.&amp;nbsp; If it doesn't then change it to do so.&amp;nbsp; You'll use that name to search for the data.&amp;nbsp; An input without an index specified will put data into the Last Chance index (usually "main" on-prem or "lastchanceindex" in Splunk Cloud).&amp;nbsp; If you search without specifying an index name then Splunk will search your default indexes (if any), which may or may not include the AWS index.&lt;/P&gt;&lt;P&gt;All Splunk data is time-sequenced.&amp;nbsp; If data is onboarded with the incorrect time then you'll have a difficult time finding it.&amp;nbsp; Verify the sourcetype's &lt;FONT face="courier new,courier"&gt;TIME_FORMAT&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;TIME_PREFIX&lt;/FONT&gt; settings match the data being ingested.&amp;nbsp; Expand the time window of your search using &lt;FONT face="courier new,courier"&gt;earliest=0 latest=+10y&lt;/FONT&gt; to see if the data is coming in with the right timestamps.&lt;/P&gt;&lt;P&gt;Of course, check the logs to make sure there are no errors getting the data from AWS.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 18:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650622#M224939</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-14T18:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650625#M224941</link>
      <description>&lt;P&gt;index is default for all my inputs and I always start my searches with index=*&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 19:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650625#M224941</guid>
      <dc:creator>henryf</dc:creator>
      <dc:date>2023-07-14T19:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650633#M224947</link>
      <description>&lt;P&gt;It's a Best Practice to send inputs to specific indexes rather than allow them to default.&lt;/P&gt;&lt;P&gt;It's a poor practice to use &lt;FONT face="courier new,courier"&gt;index=*&lt;/FONT&gt; in a query.&amp;nbsp; Anything other than a dev/test query should use specific index names.&lt;/P&gt;&lt;P&gt;Are the timestamps being extracted correctly?&lt;/P&gt;&lt;P&gt;Have you checked the logs?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 19:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650633#M224947</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-14T19:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650636#M224949</link>
      <description>&lt;P&gt;nothing is being extracted. How do You check the logs and how else would you suggest I search for what I am looking for?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 20:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650636#M224949</guid>
      <dc:creator>henryf</dc:creator>
      <dc:date>2023-07-14T20:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650652#M224957</link>
      <description>&lt;P&gt;If nothing is being extracted then either data is not getting from AWS to Splunk or the sourcetype doesn't describe the data well enough for Splunk to extract fields.&lt;/P&gt;&lt;P&gt;Start with splunkd.log to confirm the input is working and to see if there are any problems reported about the input or the data itself.&amp;nbsp; You can view the log with this query (assuming you have access)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal source=*splunkd.log&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 15 Jul 2023 00:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650652#M224957</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-15T00:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650827#M225023</link>
      <description>&lt;P&gt;data loaded when I put in that search. I don't understand how this relates to my problem though, how do I view the inputs I want?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 13:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650827#M225023</guid>
      <dc:creator>henryf</dc:creator>
      <dc:date>2023-07-17T13:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes not loading any data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650862#M225035</link>
      <description>&lt;P&gt;The query displays Splunk's internal log so you can try to determine why your inputs are not producing data.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 16:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-sourcetypes-not-loading-any-data/m-p/650862#M225035</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-17T16:02:25Z</dc:date>
    </item>
  </channel>
</rss>

