Getting Data In

replaced with new index with old one in inputs.conf

sathwikr076
Communicator

I have changed the index name for a log ingestion to a new one but the logs are still ingesting to the old index. I cannot understand why the logs are not ingesting to new index. Please let me know if anyone have any idea.

Thanks.

0 Karma

jacobpevans
Motivator

Greetings @sathwikr076,

  1. Does the index exist on the indexer that the data is being forwarded to?
  2. Did you restart the Splunk forwarder service on the machine that is monitoring the log?

Cheers,
Jacob

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

sathwikr076
Communicator

Thanks for the response. Yes, the new index exist on all the indexers and i have restarted the forwarder. checked if the index name has changed on the server by the application team and it has the new index in the inputs.conf but still it is ingesting to the old index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sathwikr076,
how do you changed destination index?

  • in inputs.conf on Universal Forwarders,
  • in overriding on Indexers?

If on UFs, after update, did you restarted Splunk on UFs?
If on Indexers, after update, did you restarted Splunk on Indexers? have you in the middle any Heavy Forwarders?

Bye.
Giuseppe

0 Karma

sathwikr076
Communicator

i have changed on UF and restarted the service through deployment server remotely as i do not have access to the server. i checked the internal logs and i can see
Metrics - group=per_index_thruput, series="new_index", kbps=0.22774524335479657, eps=0.19367014189230036, kb=7.0556640625, ev=6, avg_age=9110.833333333334, max_age=54545 but still it is ingesting to the old index. i just asked the application team to restart the forwarder directly on the server.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...