Splunk Search

New index mapped to Hdfs data input does not result -only main index shows data

deepakmurthy
Explorer

Hi Folks,

Sorry for a basic question, I am a newbie.

I have successfully installed and configured Hadoop Connect to Splunk.

  • Created a HDFS input, selected default in my index selection (Index test_stage was not created)

  • Went to my search field and entered my sourcetype resulted the event data and was showing index as main

  • After the above step, i created a new index test_stage, went to Hadoop Connect HDFS and changed my index to test_stage.

  • Reloaded index and Restarted splunk still my index does not show any results.

  • Main index shows all the data, test_stage says "No results found"

Here is the cat inputs.conf
[hdfs://x.x.x.x/user/test/stage/test_stage]
host = test_stage
sourcetype = test_XML
index = test_stage

inputs.conf shows right index, why i am still not seeing any data in my new index?

PS: I also verified roles for admin user has access to search this index.

Please suggest me where I am doing wrong and any solutions.

Thanks for looking into this question.

Tags (3)
0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

please specify your search.

Do you use

index=test_stage | head 10

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...