Getting Data In

unable to index files after deleting events and creating new sourcetype

Cuyose
Builder

I know splunk has always been a pain when trying to "fix" indexed data. I have deleted events from monitored paths in inputs because they were not indexed correctly via the sourcetype I created in props.conf. So after deleting the bad data, I fixed the props and inputs in the deployment App, pushed and verified the new files got to the servers.

Now even new files in the monitored directory are not being indexed. Ive event restarted the cluster master rolling restart of indexers, set new crcSalt values, etc. Nothing.

Tags (1)
0 Karma
1 Solution

Cuyose
Builder

I had an extra : in my input stanza. For anyone also looking for troubleshooting and that comes across this. The easy way, and what I should have done first is check the _internal index for the file path I was thinking I was monitoring.

View solution in original post

0 Karma

Cuyose
Builder

I had an extra : in my input stanza. For anyone also looking for troubleshooting and that comes across this. The easy way, and what I should have done first is check the _internal index for the file path I was thinking I was monitoring.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...