Deployment Architecture

Indexing issues

bsrikanthreddy5
Path Finder

Hi, 

In Splunk's internal log file I can see the log file was processed by Splunk to index, but when I am trying to search the same index from SH, I am not able to find the events. This is happening intermittently on a few of the log files. 

Log from  splunkd HF: 
INFO TailReader - Batch input finished reading file='/xx/log/xxxxxxx/processed/archive/processed.log_2021-01-20T12:45:01.log'

No results from below search with all-time 
index=* source="/xxx/log/xxxxxxx/processed/archive/processed.log_2021-01-20T12:45:01.log"

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @bsrikanthreddy5,

Did you try searching with wider timerange? Or "All Time". There maybe timestamp problem?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bsrikanthreddy5
Path Finder

yes, I have used an all-time in time picker. 

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...