Getting Data In

I created a new index, but why am I not able to access it via REST API to post data to the new index?

sh0stat_25
Engager

I created a new index called perftestresults and I am able to see it when I search using the below Splunk command, but when I run a post command to the index, I get the below error:

Splunk Command

| eventcount summarize=false index=* index=_* | dedup index | fields index

Error Returned:

<msg type="WARN">supplied index 'perftestresults' missing</msg>

Post I am sending:

POST https://test:8089/services/receivers/simple?index=perftestresults
payload= "This is a test
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Talk to your admin about

  • Where you are trying to send to
  • Where they defined the indexes
  • If you want to migrate to the 6.3 HTTP Event Collector

http://dev.splunk.com/view/event-collector/SP-CAAAE6M

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If the indexers' REST endpoint listing indexes doesn't list that index then I'd say that indexer doesn't have that index defined.

0 Karma

sh0stat_25
Engager

still not able to see it. trying a few other things but the API is not able to see the new index that was created.

0 Karma

sh0stat_25
Engager

where are the defined the indexes - indexes are deined in 4 indexers

where you are trying to send to - sending to indexer

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Did you define the index on the receiving instance?

0 Karma

sh0stat_25
Engager

That i am not sure about as i am only the consumer. i will have to check with my Splunk SA.

would you main explaining how i would go about doing that so i can have him cross check

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Are you on one standalone Splunk or in a distributed environment?

0 Karma

sh0stat_25
Engager

distributed environment

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What do you get when you GET https://test:8089/services/data/indexes against the same Splunk instance you POSTed to?

sh0stat_25
Engager

i get other indexes which are listed but i dont get the one that i am looking for which is the "perftestresults" but it is displayed when i search splunk for indexes which is strange.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...