Getting Data In

Why is my index list not complete for Data Input Files and Directories?

kent_farries
Path Finder

When trying to pick my index from the list in Data Input Files & Directories it does not show. For some reason it only goes to session_start and all the indexes after that do not show. If I use the UDP input they all show up.

Splunk 6.2 on Windows Server 2012 R2
Google Chrome 38.x
IE 11

I don't know if this has anything to do with the above but Splunk stopped indexing my files in a directory called Varonis. When I created a new index index called abcd it worked fine.

Tags (3)
1 Solution

kent_farries
Path Finder

Thanks, I checked and it does exist

I managed to find a work around as maybe this is a bug in the 6.2 GUI.

Data Input, Files & Directories

  1. Point to an empty folder

  2. Use the default data index instead of trying to select one since it will not got past the letter s in my case.

  3. After the Data Input is created go back in and change the index from default to the one I want which did not show above. Yes this works just fine.

  4. Add files to the folder. Did not want to do this before since it would start indexing the files into main.

Take care.

View solution in original post

0 Karma

kent_farries
Path Finder

Thanks, I checked and it does exist

I managed to find a work around as maybe this is a bug in the 6.2 GUI.

Data Input, Files & Directories

  1. Point to an empty folder

  2. Use the default data index instead of trying to select one since it will not got past the letter s in my case.

  3. After the Data Input is created go back in and change the index from default to the one I want which did not show above. Yes this works just fine.

  4. Add files to the folder. Did not want to do this before since it would start indexing the files into main.

Take care.

0 Karma

Raghav2384
Motivator

Use this too see if the index you are referring to exists:
|REST /services/data/indexes|dedup title|table title. Also check the inside db/to see if the index is listed.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...