Getting Data In

Splunk Suddenly Stops Indexing

matthewcanty
Communicator

I'm new to Splunk - as in this morning - but have been shown around it a few times. I've just downloaded the free version and installed everything fine. I have setup an indexer, and started adding data from a folder location.

The summary shows all of the files in the directory and has found the two sources which I wanted to see which is great.

Under Source Types I have a source DataNormalisation and its Last Update time is "Tue Mar 27 09:32:33 2012". When I click it and go for Last 7 Days the last message is from the 23rd. If I look in the file the last message is today - because the service is running now and logging now.

What am I doing wrong?

Head/Tail issue?

Please see the following three images in order as a proof...

Page 1 | Page 2 | Page 3

See on Page 2 the last message is on 26th...

0 Karma
1 Solution

matthewcanty
Communicator

Problem seems to be related to Index. I was using a new Index which I had made, when I just tried using the main Index it started straight away.

Is this a limitation of the free version?

View solution in original post

0 Karma

matthewcanty
Communicator

Problem seems to be related to Index. I was using a new Index which I had made, when I just tried using the main Index it started straight away.

Is this a limitation of the free version?

0 Karma

Drainy
Champion

By default Splunk will search and the search app references the main index. If you search index=YOURINDEX it should return all your events

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...