Deployment Architecture

Why do I not see data from an index after restart?

power12
Communicator

Hello SPlunkers ,

 

I am not seeing data for a particular index after restart

3/29/23
5:00:34.647 PM
03-30-2023 00:00:34.647 +0000 INFO HotDBManager [7073 indexerPipe] - closing hot mgr for idx=abc
component = HotDBManagerhost = abc index = _internalsource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.618 PM
03-30-2023 00:00:34.618 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Handling shutdown or signal, reason=1
component = IndexWriterhost = abc index = _internals ource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.601 PM
03-30-2023 00:00:34.601 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Sync before shutdown

Restarted splunk again and then enabled and disabled the index but still not seeing data...checked source..it is showing data

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify you still have permission to access to the index.

Make sure the indexes.conf settings for the index did not change.

Confirm data is still being forwarded from the source to Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...