Splunk Search

Why am I unable to search event data for license_usage.log?

srikanth1213
Path Finder

Hi Guys, I am unable to search the event data for license_usage.log , whereas I can see the log file getting updated in the server. kindly help if I have to enable it elsewhere to display in search.

0 Karma
1 Solution

srikanth1213
Path Finder

Hi , We were able to fix the issue by enabling the logging of the directory "$SPLUNK_HOME\var\log\splunk " under data inputs in Splunk UI ..thank you.

View solution in original post

0 Karma

srikanth1213
Path Finder

Hi , We were able to fix the issue by enabling the logging of the directory "$SPLUNK_HOME\var\log\splunk " under data inputs in Splunk UI ..thank you.

0 Karma

PPape
Contributor

Are you in an clustered enviroment or in an single instance enviroment?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

IIRC, your role needs access to the _internal index to read that log.

---
If this reply helps you, Karma would be appreciated.
0 Karma

srikanth1213
Path Finder

Well , I logged in as an admin , and it does has access to _internal index as I am able to search the data when I give index=_internal ...

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...