Getting Data In

Data upload from splunk ui is successful, but data is not appearing in search

jagdish0886
Explorer

Hi,
I have uploaded the data to splunk, but while searching the data doesnt appear, I have shared the screenshots as well. Can you please help here.
Index used - default
log file type - .log
search criteria - all time
Splunk version of docker - store/splunk/splunk:7.3

alt text

0 Karma
1 Solution

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

View solution in original post

0 Karma

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

0 Karma

jagdish0886
Explorer

adding few more details:
When I upload the data from Splunk UI, it notifies that data is successfully uploaded, however
indexed data doesn't reflect in Splunk indexed data path opt/splunk/var/lib/splunk/spice-index/db and hence not searchable from splunk UI. Please help how to make the data searchable:

Index used: default and custom (both same issue)
search criteria: all time
splunk docker container: version store/splunk/splunk:7.3  developer licence
file size : 500 KB file type .log
browser: tried with chrome and IE
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...