Getting Data In

Why are my UDP inputs not showing up in my metrics.log?

rene847
Path Finder

Hi all,

I would like to know....

I have a functional index named "phone"
I have 120 IP (with no host) defined in inputs.conf on Universal Forwarders with index=phone.

Example:

[udp://aaa.bbb.ccc.ddd:514]
        source = sip_syslog
        sourcetype = phone:siplab
        connection_host = none
        acceptFrom = aaa.bbb.ccc.ddd
        disabled = false
        index = phone

I find data with search on the search head with index=phone and my index on the server grows (so it's functional), but when I run this command (Highest-usage indexes), I don't have my Phone index. Why?

See my query:
index="_internal" source="*metrics.log" per_index_thruput | eval GB=kb/(1024*1024) | stats sum(GB) as total by series date_mday | sort total | fields + date_mday,series,total | reverse

However, with this query, I see my index:
index=_internal source=license_usage.log type=Usage | stats sum(b) by idx | sort sum(b) |reverse

I don't know why I don't have my index with the first query (made by Splunk)?

I would like just 1 report with ALL index for one day (first query). Do you have an idea?

Thanks in advance
Best Regards
Rene R.

0 Karma
1 Solution

tskinnerivsec
Contributor

is your index name all lower case ? index=phone, If not, it should be lower case, can cause problems if not.

View solution in original post

0 Karma

tskinnerivsec
Contributor

is your index name all lower case ? index=phone, If not, it should be lower case, can cause problems if not.

0 Karma

rene847
Path Finder

No, its correct.... it's a bad exemple
I corrected my post.

but my problem is still present !!!!!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...