I have been adding some log data in my splunk web UI but I am not able to view it even though the manager shows that those logs have been added.
- check your licenses to see if you have reached your daily maximum indexing. Manager » Licensing.
- If that is okay, identify your Splunk user role permissions. Manager » Access controls » Roles » ; scroll to the bottom and check to make sure "Index" includes the index your data is pointing to.
If all that checks out, I recommend installing the Splunk on Splunk app to help you identify the problem.
View solution in original post