Installation

Installed Splunk but no Data!

canton
New Member

I have installed Splunk on server and can login to splunk and browse but no data is showing in search section waht so ever.

I have also configured via Manager » Data inputs » Files & Directories.

But still no luck what could be wrong?

Thanks in advance

Tags (1)
0 Karma
1 Solution

Genti
Splunk Employee
Splunk Employee

So, when you go to Manager » Data inputs » Files & Directories do you see the file/directory you added as listed? And does it show a number of files next to it?

Is this directory perhaps owned by a different user and the splunk service does not have appropriate permissions to monitor/read the files within?

Are you searching using the "all time" time-range? Perhaps this is historic data and not showing up in the timeframe you are searching?

Lastly, if you search for "index=_internal", do you see any data show up?

View solution in original post

Genti
Splunk Employee
Splunk Employee

So, when you go to Manager » Data inputs » Files & Directories do you see the file/directory you added as listed? And does it show a number of files next to it?

Is this directory perhaps owned by a different user and the splunk service does not have appropriate permissions to monitor/read the files within?

Are you searching using the "all time" time-range? Perhaps this is historic data and not showing up in the timeframe you are searching?

Lastly, if you search for "index=_internal", do you see any data show up?

Genti
Splunk Employee
Splunk Employee

well, no, you have to be careful here. This means that you are receiving internal data. What about your OTHER data. Are you receiving the logs from the files that you already included in your data inputs?

0 Karma

canton
New Member

mmm after doing what you advised "index=_internal" all seemed to work or it may have been a coincidence.

regardless thank you for your help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...