Splunk Enterprise

Why can I not see the data in Splunk UI?

Santosh2
Path Finder

Hi all, I can see the logs coming in from a particular source=das*.log through backend Linux but when I search with the same source I cannot see data in ui 

One more thing if I use with index name and source also I am not getting any data in ui 

Note: when I searched with internal index I could see logs from that host IP but not from the source in ui 

Can any one help on this issue.

 

 

Labels (1)
Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Santosh2 - You can take some predefined steps in case of data input issues:

  • Check if you have inputs.conf entry for these files
  • Have you specified the right index?
  • Have you created that index on the Indexer?
  • Make sure you are not filtering the data with transforms.conf config
    • check for queue=null line in transforms.conf 
    • If you see any, make sure it's not related to your data
  • Make sure you are receiving other data from that host.
    • index=_internal host=<hostname-that-has-inputs.conf> 
  • Make sure you have permission to read the index data and also make sure no other restriction being applied.
    • You can check with Splunk Admin.

 

I hope this helps!!! Upvote/karma would be appreciated!!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...