Sorry for a basic question, I am a newbie.
I have successfully installed and configured Hadoop Connect to Splunk.
Created a HDFS input, selected default in my index selection (Index test_stage was not created)
Went to my search field and entered my sourcetype resulted the event data and was showing index as main
After the above step, i created a new index teststage, went to Hadoop Connect HDFS and changed my index to teststage.
Reloaded index and Restarted splunk still my index does not show any results.
Main index shows all the data, test_stage says "No results found"
Here is the cat inputs.conf
host = teststage
sourcetype = testXML
index = teststage
inputs.conf shows right index, why i am still not seeing any data in my new index?
PS: I also verified roles for admin user has access to search this index.
Please suggest me where I am doing wrong and any solutions.
Thanks for looking into this question.
please specify your search.
Do you use
index=test_stage | head 10