Getting Data In

Upload failed with WARN : supplied index 'xxx' missing?

SeanBatt
Explorer

We're using Splunk Cloud 8.2.2202.1 and have a data upload issue.

I can upload a CSV  using the Add Data button in Settings menu into index=sandbox, but can't upload to my newly created index=xxx. I get a

"supplied index 'xxx' missing" error.

After data loaded into sandbox (showing I have accounted for adding a timestamp) I can

index=sandbox | collect index=xxx sourcetype=hec testmode=false

to put the data into xxx which seems to me proves index=xxx exists despite the contents of the error message.

1. Can anyone suggest what I might be doing wrong in getting my csv data into the correct index without taking a detour through index=sandbox?

2. I suspect there might be more log information about the failure somewhere, but I've looked in index=_internal and have not seen anything relevant. Is there somewhere else I can look? 

3. We have been maddened by a string of silent failures in our use of Splunk in the past weeks and I wonder if there isn't a logging verbosity control that we could use to make it clearer what is happening (or not happening) with our Splunk operations? 

Kind Regards,

Sean

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hiu @SeanBatt,

when you create an index in Splunk Cloud, uaually a message appears similar to this: "the index will be available in few minutes"

probably there'a a delay in index creation that gives a problem to your Add data.

Please try to create the index before Add data (you should already have created the index) and then repeat Add data.

Ciao.

Giuseppe

0 Karma

SeanBatt
Explorer

The index must be available as I was able to use collect to add data to it. 
Five hours after creation, I still can't upload a csv file of data to it.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you see that this index is available in Cloud Monitoring Console (CMC -> Indexing -> Index Detail)?
0 Karma

SeanBatt
Explorer

Yes, the index is shown Cloud Monitoring Console's Index Detail dashboard. It says there's one event in it which was the one I pushed over using collect.

0 Karma

ojensen
Explorer

I had the same symptoms.

In my case, the root cause of the problem was that I was attempting to use the "Add Data" upload functionality on the search-head (i.e. at https://myhost.splunkcloud.com/) instead of at the IDM (i.e. at https://idm.myhost.splunkcloud.com/). Attempting to upload it there worked without problems.

 

I do find it frustrating that both the IDM and the search head seem to use the same interface and you just need to expect various chunks of functionality to be broken on one and work on the other, but I guess as far as things go it's not too bad to just have a principle where "if something fails on one, try it on the other".

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...