We have just set up Distributed search with 2 indexers and one search node. Our data source is a folder with log files. The splunkd.log show many lines with the following
WatchFile - using folow tail will begin reading EOF for F:\splunk\index01....
But we get No results when searching. Are we being impatient?
the forwarder has a default thruput limit of 256KBps, and is queuing a large file
the events have a misconfigured sourcetype, causing the timestamp/timezone to be misinterpreted, and the events to be in the future (or centuries in the past). Verify with a real-time "alltime" search to see the events that are currently received.
you also can check in your license logs to see is the file has been indexed (index=_internal source=license_usage.log "myfile" )