Getting Data In

Data upload from splunk ui is successful, but data is not appearing in search

jagdish0886
Explorer

Hi,
I have uploaded the data to splunk, but while searching the data doesnt appear, I have shared the screenshots as well. Can you please help here.
Index used - default
log file type - .log
search criteria - all time
Splunk version of docker - store/splunk/splunk:7.3

alt text

0 Karma
1 Solution

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

View solution in original post

0 Karma

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

0 Karma

jagdish0886
Explorer

adding few more details:
When I upload the data from Splunk UI, it notifies that data is successfully uploaded, however
indexed data doesn't reflect in Splunk indexed data path opt/splunk/var/lib/splunk/spice-index/db and hence not searchable from splunk UI. Please help how to make the data searchable:

Index used: default and custom (both same issue)
search criteria: all time
splunk docker container: version store/splunk/splunk:7.3  developer licence
file size : 500 KB file type .log
browser: tried with chrome and IE
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...