Getting Data In

Why are my UDP inputs not showing up in my metrics.log?

rene847
Path Finder

Hi all,

I would like to know....

I have a functional index named "phone"
I have 120 IP (with no host) defined in inputs.conf on Universal Forwarders with index=phone.

Example:

[udp://aaa.bbb.ccc.ddd:514]
        source = sip_syslog
        sourcetype = phone:siplab
        connection_host = none
        acceptFrom = aaa.bbb.ccc.ddd
        disabled = false
        index = phone

I find data with search on the search head with index=phone and my index on the server grows (so it's functional), but when I run this command (Highest-usage indexes), I don't have my Phone index. Why?

See my query:
index="_internal" source="*metrics.log" per_index_thruput | eval GB=kb/(1024*1024) | stats sum(GB) as total by series date_mday | sort total | fields + date_mday,series,total | reverse

However, with this query, I see my index:
index=_internal source=license_usage.log type=Usage | stats sum(b) by idx | sort sum(b) |reverse

I don't know why I don't have my index with the first query (made by Splunk)?

I would like just 1 report with ALL index for one day (first query). Do you have an idea?

Thanks in advance
Best Regards
Rene R.

0 Karma
1 Solution

tskinnerivsec
Contributor

is your index name all lower case ? index=phone, If not, it should be lower case, can cause problems if not.

View solution in original post

0 Karma

tskinnerivsec
Contributor

is your index name all lower case ? index=phone, If not, it should be lower case, can cause problems if not.

0 Karma

rene847
Path Finder

No, its correct.... it's a bad exemple
I corrected my post.

but my problem is still present !!!!!

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...