Splunk Search

Its showing nothing in Splunk logs window for any kind of search

jaikratsingh
New Member

Ok so I ran command

splunk clean eventdata

And now my Splunk is not working as earlier. I am able to ADD log file/folder but its not showing anything in search even for any time frame.

I was seeing lots of Sources and one Host in

Search-> Data Summary

but not any more.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The command you ran would have deleted all the events in splunk. If you have existing inputs they will not reindex the data you have deleted unless you remove the relevant fishbucket entries. If you want to reindex everything then on your forwarder delete the directory $SPLUNK_HOME/var/lib/splunk/fishbucket. To reindex a single file have a look at the documentation for btprobe https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSuppor...

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...