Deployment Architecture

Indexing issues

bsrikanthreddy5
Path Finder

Hi, 

In Splunk's internal log file I can see the log file was processed by Splunk to index, but when I am trying to search the same index from SH, I am not able to find the events. This is happening intermittently on a few of the log files. 

Log from  splunkd HF: 
INFO TailReader - Batch input finished reading file='/xx/log/xxxxxxx/processed/archive/processed.log_2021-01-20T12:45:01.log'

No results from below search with all-time 
index=* source="/xxx/log/xxxxxxx/processed/archive/processed.log_2021-01-20T12:45:01.log"

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @bsrikanthreddy5,

Did you try searching with wider timerange? Or "All Time". There maybe timestamp problem?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bsrikanthreddy5
Path Finder

yes, I have used an all-time in time picker. 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...