Splunk Search

unable to get all event data to newly created index

Jyo_Reel
Engager

Hi Team,

I can see events related to all hosts in internal index but the only few hosts data is available in newly created index. Please help me to troubleshoot the issue.

Thanks in advance.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The _internal index collects Splunk's internal (hence the name) events. Generally, the underscore-beginning indexes are internal to Splunk and you can expect the data there to be governed by default Splunk settings (you can adjust some of them like retention period but that is not needed for them to work out of the box).

Everything else is up to you. We don't know what are your sources, what does your onboarding process look like what are your indexes and how should the data get into them.

So the question you stated is not for us - it's for your Splunk admins and architects. They should know what data should be ingested from where and land into which index. They should also know whether you are allowed to have access to that data because not everyone usually has access to every index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jyo_Reel ,

in _internal index you see the Splunk logs, if you need other logs (e.g. operative system or appications), you have to install also the rerated add-ons (Linux https://splunkbase.splunk.com/app/833 or windows https://splunkbase.splunk.com/app/742 ) enabling the input stanzas that you want.

Having the _internal logs from all hosts is a good starting point because it means that you correctly configured your connections and there isn't any connection issue.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...