Splunk Search

unable to get all event data to newly created index

Jyo_Reel
Engager

Hi Team,

I can see events related to all hosts in internal index but the only few hosts data is available in newly created index. Please help me to troubleshoot the issue.

Thanks in advance.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The _internal index collects Splunk's internal (hence the name) events. Generally, the underscore-beginning indexes are internal to Splunk and you can expect the data there to be governed by default Splunk settings (you can adjust some of them like retention period but that is not needed for them to work out of the box).

Everything else is up to you. We don't know what are your sources, what does your onboarding process look like what are your indexes and how should the data get into them.

So the question you stated is not for us - it's for your Splunk admins and architects. They should know what data should be ingested from where and land into which index. They should also know whether you are allowed to have access to that data because not everyone usually has access to every index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jyo_Reel ,

in _internal index you see the Splunk logs, if you need other logs (e.g. operative system or appications), you have to install also the rerated add-ons (Linux https://splunkbase.splunk.com/app/833 or windows https://splunkbase.splunk.com/app/742 ) enabling the input stanzas that you want.

Having the _internal logs from all hosts is a good starting point because it means that you correctly configured your connections and there isn't any connection issue.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...