Getting Data In

Why all my sourcetypes are not showing up in web GUI?

rfeddal
Engager

Hi,

I have an index with 7 sourcetypes. For a particular reason, I had to delete the index. Made a refresh, then I re-created it.

But when I checked if all my sourcetypes are there, I found only 6. One of them haven't been added by splunk. I don't understad why?

Plus, I've created a new index with a new sourcetype. But after restarting the splunk service, nothing is showing up in the Web GUI when I made a research on this new index.

I don't understand what is happening.

Did someone has the same issue? And know how to resolve it?

Thank you.

Labels (1)
Tags (1)
0 Karma
1 Solution

rfeddal
Engager

I resolved my issue:
The source added in the second index was the same of the first one. So I deleted the second sourcetype, deleted the both indexes and recreated them, then it I re-found my 7 sourcetypes.

View solution in original post

0 Karma

rfeddal
Engager

I resolved my issue:
The source added in the second index was the same of the first one. So I deleted the second sourcetype, deleted the both indexes and recreated them, then it I re-found my 7 sourcetypes.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you do: “splunk cmd btool props list | egrep ‘^[‘ “do you see those sourcetypes? And have you those event already on your indexers?

Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...