Splunk Search

New index mapped to Hdfs data input does not result -only main index shows data

deepakmurthy
Explorer

Hi Folks,

Sorry for a basic question, I am a newbie.

I have successfully installed and configured Hadoop Connect to Splunk.

  • Created a HDFS input, selected default in my index selection (Index test_stage was not created)

  • Went to my search field and entered my sourcetype resulted the event data and was showing index as main

  • After the above step, i created a new index test_stage, went to Hadoop Connect HDFS and changed my index to test_stage.

  • Reloaded index and Restarted splunk still my index does not show any results.

  • Main index shows all the data, test_stage says "No results found"

Here is the cat inputs.conf
[hdfs://x.x.x.x/user/test/stage/test_stage]
host = test_stage
sourcetype = test_XML
index = test_stage

inputs.conf shows right index, why i am still not seeing any data in my new index?

PS: I also verified roles for admin user has access to search this index.

Please suggest me where I am doing wrong and any solutions.

Thanks for looking into this question.

Tags (3)
0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

please specify your search.

Do you use

index=test_stage | head 10

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...