Installation

Splunk 6 indexing

kmattern
Builder

I just upgraded to Splunk 6.0.2. Why did it override all of my indexes. In 5.0.4 I specified a separate index for each of my major sourcetypes. But Splunk 6 blithely decided to dump everything into main. What gives?

Tags (3)
0 Karma

kmattern
Builder

Sigh... The forwarder was sending the log to multiple indexers and specifying the index as main. I'll have to find another way to get the data consumed.

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

Did you put your configuration files in the default directory vs local?

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

It really shouldn't of overrided the configurations if you have things in local.

Do you have enterprise support? If so, can you get a ticket opened up and let me know the ticket number..

0 Karma

kmattern
Builder

I always use local. When I set up 5.0.4 six months ago I defined all my indexes then. If I search the original indexes for events prior to the upgrade, everything is there.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...