Splunk Enterprise

With data not indexing, what are other steps to follow to get data in index XYZ?

Santosh2
Path Finder

Index=XYZ  source= abc*.logs host=kfg 

So I when I checked in internal index data is coming from host, I checked forwarder server class mapping is fine, I could see the data is deploying. But still cannot see data.

What other steps i need to follow to get data in index XYZ

 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Santosh2,

maybe the timestamp isn't correctly parsed, try to search something special of your logs in a very large time period.

Then, if you're searching logs in the first 11 days of the month, try to search the 1st of may (01/05/2022) at the 5th of january (05/01/2022).

Then, are you sure about index?

then, try to add an asterisk at the beginning of the source, maybe there's the full path and/ot an asterisk at the end of host, maybe there's the FQDN name instead of the hostname.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...