Splunk Web doesn't show the events at times. If I restart and log in, it will show the events, but after some time, events are not displayed. It shows total events, but the details are not displayed
Also, the main page doesn't show the summary of events indexed. Usually it should total events and indexes.
What could be the problem? This leads to me restarting splunkd service every time.
... | table _raw
check Wats there. If your logs are json Splunk will take time to load... Post the screen shot
What do you see in the splunk logs?
http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/WhatSplunklogsaboutitself
there are multiple logs in C:\Program Files\Splunk\var\log\splunk
. is there any particular log that you are looking for?
start with splunkd.... see if anything sticks out.
splunkd didnt show anything odd