I setup a new monitor on a Json file last week to add the contents to a new index. Once I got finished the new index would not show any events. I messed with it for 4 days until I decided to just use an older Index that was built at some point before I joined the company. I have no idea on the approx age of this index other than the earliest index was 7 months ago. I know an upgrade was done since then.
The issue I seem to be facing is that any new index I create is not getting data but if I user an older one it works. I don't even know where to begin on trying to solve this so any input is appreciated. I did see in splunkd log something about a "string index out of range" and found a solution to go and basically increase MAX_SEGMENT = 1024 - change it to MAX_SEGMENT = 4096 in $SPLUNK_HOME/bin/scrubber.py.
That did not fix anything. Thank you!