Deployment Architecture

Files in folders indexed but no results showing in search

bshamsian
Path Finder

I setup a directory to be scanned.  I went to Manager » Data inputs » Add data » Files & directories & clciked the new button and went thru the data preview and picked a file and made sure it looks ok with the given sourcetype that I created.  Once everything looked ok I changed the input from a single file to a folder - so the path to input file is something like this:

/opt/readonly/logs/event_recorder/2012-12-*

Once I created the new data input I see the folder in the input lists and I see that splunk has indexed over 300 files and the count goes up as new files come in.  However no results are returned in search for anything from these files.  I tried searching based on HOST field or source filed or sourcetype field and nothing comes back in search.

Index was set to default so they should have gone to main index. Tried using index=* but did not make any difference.

How can I find out what happened and what did splunk do with the data.

Splunk version 4.3

Tags (1)
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

What timeframe are you searching across? It's possible that the time extraction or timezone is incorrect, so if you are doing a real-time search over the past 5 minutes, for instance, you will never see anything.

Perform your search over all time and see if any data comes back. If it does, you'll need to get the time extraction and timezone set correctly.

bshamsian
Path Finder

I thought about that and changed timeframe to all time but it not make a difference.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...