Yesterday, I created an index and set up the appropriate file inputs, which proceeded to slurp data into the index.
When I got in today I had a message something along the lines of being unable to import data into an index that doesn't exist.
Looking at the filesystem, the index files seem to be in place, however it is not listed via the WebUI.
Any ideas on how to get splunk to see this index again? (or why it would have disappeared)
Thanks,
Pete
Apparently the only problem was the stanza was missing from the indexes.conf.
did you attempt to restart splunk by chance to see if it shows up?
Splunk Version: 6.0
Splunk Build: 182037
What version of Splunk?