Getting Data In

Upload failed with WARN : supplied index 'xxx' missing?

SeanBatt
Explorer

We're using Splunk Cloud 8.2.2202.1 and have a data upload issue.

I can upload a CSV  using the Add Data button in Settings menu into index=sandbox, but can't upload to my newly created index=xxx. I get a

"supplied index 'xxx' missing" error.

After data loaded into sandbox (showing I have accounted for adding a timestamp) I can

index=sandbox | collect index=xxx sourcetype=hec testmode=false

to put the data into xxx which seems to me proves index=xxx exists despite the contents of the error message.

1. Can anyone suggest what I might be doing wrong in getting my csv data into the correct index without taking a detour through index=sandbox?

2. I suspect there might be more log information about the failure somewhere, but I've looked in index=_internal and have not seen anything relevant. Is there somewhere else I can look? 

3. We have been maddened by a string of silent failures in our use of Splunk in the past weeks and I wonder if there isn't a logging verbosity control that we could use to make it clearer what is happening (or not happening) with our Splunk operations? 

Kind Regards,

Sean

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hiu @SeanBatt,

when you create an index in Splunk Cloud, uaually a message appears similar to this: "the index will be available in few minutes"

probably there'a a delay in index creation that gives a problem to your Add data.

Please try to create the index before Add data (you should already have created the index) and then repeat Add data.

Ciao.

Giuseppe

0 Karma

SeanBatt
Explorer

The index must be available as I was able to use collect to add data to it. 
Five hours after creation, I still can't upload a csv file of data to it.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you see that this index is available in Cloud Monitoring Console (CMC -> Indexing -> Index Detail)?
0 Karma

SeanBatt
Explorer

Yes, the index is shown Cloud Monitoring Console's Index Detail dashboard. It says there's one event in it which was the one I pushed over using collect.

0 Karma

ojensen
Explorer

I had the same symptoms.

In my case, the root cause of the problem was that I was attempting to use the "Add Data" upload functionality on the search-head (i.e. at https://myhost.splunkcloud.com/) instead of at the IDM (i.e. at https://idm.myhost.splunkcloud.com/). Attempting to upload it there worked without problems.

 

I do find it frustrating that both the IDM and the search head seem to use the same interface and you just need to expect various chunks of functionality to be broken on one and work on the other, but I guess as far as things go it's not too bad to just have a principle where "if something fails on one, try it on the other".

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...