Splunk Search

New index mapped to Hdfs data input does not result -only main index shows data

deepakmurthy
Explorer

Hi Folks,

Sorry for a basic question, I am a newbie.

I have successfully installed and configured Hadoop Connect to Splunk.

  • Created a HDFS input, selected default in my index selection (Index test_stage was not created)

  • Went to my search field and entered my sourcetype resulted the event data and was showing index as main

  • After the above step, i created a new index test_stage, went to Hadoop Connect HDFS and changed my index to test_stage.

  • Reloaded index and Restarted splunk still my index does not show any results.

  • Main index shows all the data, test_stage says "No results found"

Here is the cat inputs.conf
[hdfs://x.x.x.x/user/test/stage/test_stage]
host = test_stage
sourcetype = test_XML
index = test_stage

inputs.conf shows right index, why i am still not seeing any data in my new index?

PS: I also verified roles for admin user has access to search this index.

Please suggest me where I am doing wrong and any solutions.

Thanks for looking into this question.

Tags (3)
0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

please specify your search.

Do you use

index=test_stage | head 10

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...