HI gcusello,
Thank you for your quick response,
Let me clarify again the issue am getting,
I want to add other inputs data from network devices (Syslog sender) into Splunk,
before I had few devices (8devices) configured well and generating logs, and I wanted to add the other 20 devices but after I did this Splunk configuration as I do before, I can't see its logs not only that and this seems has affected the 8 devices configured before, for now, the logs are not available as it appeared before on the 8 devices, the entire index for this specific devices its not available on the other index ,when you do search: index=* to see all index you only see other not this mentioned above.
when I do search: index=xxx is not available.
BUT the issue is that after doing the configuration, I can't see the data of those inputs in search?
even the previous 8 devices that before I use to see its logs I can't see it? even its index is not available as before? It seems like it was disabled/deleted. how to check it?
challenge; when I do search in one week I can see the logs of 8 previous devices before adding the 20 devices but currently not, I don't know where the problem comes from?????
... View more