Getting Data In

Splunk Suddenly Stops Indexing

matthewcanty
Communicator

I'm new to Splunk - as in this morning - but have been shown around it a few times. I've just downloaded the free version and installed everything fine. I have setup an indexer, and started adding data from a folder location.

The summary shows all of the files in the directory and has found the two sources which I wanted to see which is great.

Under Source Types I have a source DataNormalisation and its Last Update time is "Tue Mar 27 09:32:33 2012". When I click it and go for Last 7 Days the last message is from the 23rd. If I look in the file the last message is today - because the service is running now and logging now.

What am I doing wrong?

Head/Tail issue?

Please see the following three images in order as a proof...

Page 1 | Page 2 | Page 3

See on Page 2 the last message is on 26th...

0 Karma
1 Solution

matthewcanty
Communicator

Problem seems to be related to Index. I was using a new Index which I had made, when I just tried using the main Index it started straight away.

Is this a limitation of the free version?

View solution in original post

0 Karma

matthewcanty
Communicator

Problem seems to be related to Index. I was using a new Index which I had made, when I just tried using the main Index it started straight away.

Is this a limitation of the free version?

0 Karma

Drainy
Champion

By default Splunk will search and the search app references the main index. If you search index=YOURINDEX it should return all your events

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...