Archive
Highlighted

splunk 6.6 installed just now, index=_internal sourcetype=splunkd says no results, is it a bug?

Explorer

Hi,
Just now installed splunk.6.6 on Windows10 and loggedin. Uninstalled it.
installed again with new location for SPLUNKHOME to c:\splunk\
Installation is successful, created a new user, changed password search query index=
internal sourcetype=splunkd says no results.

tried with index=* , again no results.
time window changed to 24 hours by default, instead of All time.

Regards,
Lakshmi K

Tags (2)
0 Karma
Highlighted

Re: splunk 6.6 installed just now, index=_internal sourcetype=splunkd says no results, is it a bug?

Champion

this is an usual one. the _internal index gets data later.
trying adding some sample data / log files, the tutorial data (http://www.splunk.com/base/images/Tutorial/Sampledata.zip) .. then internal index will get data.

0 Karma
Highlighted

Re: splunk 6.6 installed just now, index=_internal sourcetype=splunkd says no results, is it a bug?

Explorer

http://localhost:8000/en-US/manager/search/apps/local
SplunkForwarder
SplunkLightForwarder
enabled.
As its my local installation, I moved the local folder from C:\Splunk\etc\apps\SplunkForwarder\ away, restarted splunk. Started working.
Mus anwered earlier

0 Karma
Highlighted

Re: splunk 6.6 installed just now, index=_internal sourcetype=splunkd says no results, is it a bug?

Explorer

Hi,
https://answers.splunk.com/answers/335162/how-do-i-troubleshoot-why-splunk-has-stopped-index.html
Mus answered this

in
htheretp://localhost:8000/en-US/manager/search/apps/local
forward enabled. Disabled it. Restarted splunk.
Issue resolved

0 Karma