Getting Data In

replaced with new index with old one in inputs.conf

sathwikr076
Communicator

I have changed the index name for a log ingestion to a new one but the logs are still ingesting to the old index. I cannot understand why the logs are not ingesting to new index. Please let me know if anyone have any idea.

Thanks.

0 Karma

jacobpevans
Motivator

Greetings @sathwikr076,

  1. Does the index exist on the indexer that the data is being forwarded to?
  2. Did you restart the Splunk forwarder service on the machine that is monitoring the log?

Cheers,
Jacob

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

sathwikr076
Communicator

Thanks for the response. Yes, the new index exist on all the indexers and i have restarted the forwarder. checked if the index name has changed on the server by the application team and it has the new index in the inputs.conf but still it is ingesting to the old index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sathwikr076,
how do you changed destination index?

  • in inputs.conf on Universal Forwarders,
  • in overriding on Indexers?

If on UFs, after update, did you restarted Splunk on UFs?
If on Indexers, after update, did you restarted Splunk on Indexers? have you in the middle any Heavy Forwarders?

Bye.
Giuseppe

0 Karma

sathwikr076
Communicator

i have changed on UF and restarted the service through deployment server remotely as i do not have access to the server. i checked the internal logs and i can see
Metrics - group=per_index_thruput, series="new_index", kbps=0.22774524335479657, eps=0.19367014189230036, kb=7.0556640625, ev=6, avg_age=9110.833333333334, max_age=54545 but still it is ingesting to the old index. i just asked the application team to restart the forwarder directly on the server.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...