Deployment Architecture

Why do I not see data from an index after restart?


Hello SPlunkers ,


I am not seeing data for a particular index after restart

5:00:34.647 PM
03-30-2023 00:00:34.647 +0000 INFO HotDBManager [7073 indexerPipe] - closing hot mgr for idx=abc
component = HotDBManagerhost = abc index = _internalsource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
5:00:34.618 PM
03-30-2023 00:00:34.618 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Handling shutdown or signal, reason=1
component = IndexWriterhost = abc index = _internals ource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
5:00:34.601 PM
03-30-2023 00:00:34.601 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Sync before shutdown

Restarted splunk again and then enabled and disabled the index but still not seeing data...checked is showing data

Labels (1)
0 Karma


Verify you still have permission to access to the index.

Make sure the indexes.conf settings for the index did not change.

Confirm data is still being forwarded from the source to Splunk.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...