Getting Data In

DATA not feeding in INDEX : Splunk

vivekg72
Explorer

Hi

I have got 5 node SPLUNK .

NODE1 : Master + License Manager
Node 2 : Indexer - peer
Node 3 : Indexer - Peer
Node 4 : Indexer - Peer
Node 5 : Search head

All is working fine . Now I need to create a new index for test purpose . and push one file in that index

Thus I have done following :

In master Node , We have a file called indexes.conf under :
/apps/splunk/etc/master-apps/app-infrastructure-loganalysis/local

I have added a few index lines :
[indexwinelksynclogs]
homePath = /data/splunk/indexwinelksynclogs/db
coldPath = /data/splunk/indexwinelksynclogs/colddb
thawedPath = /data/splunk/indexwinelksynclogs/thaweddb
repFactor = auto

0 Karma

vivekg72
Explorer

Therefter I did following in master :

splunk apply cluster-bundle
splunk show cluster-bundle-status

I can see new index file is deployed in All Index servers . I have restarted whole cluster
and I can see index in UI

but When I try to push data , it does not work .. nothing goes in index

Can u please help me ASAP ?

0 Karma

vivekg72
Explorer

Hi

I have added following lines in input.conf of splunk forwarder

[monitor://D:\PTP\Daily*.csv]
disabled = false
sourcetype = indexwinelksynclogs
index = indexwinelksynclogs

0 Karma

vivekg72
Explorer

There are two more stanza in input file ( using old indexes ) and I can see data in those indexes updated regularly

but not in new Index .

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please say more about how you are pushing data and how you are searching for it. How are you specifying the index name? Are you specifying the correct index?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...