Hello Team, I hope you are doing well. Recently i am going through a critical issue on my splunk entreprise. I used to receive logs from switches and firewalls and everything was fine. Until yesterday, splunk stopped indexing everything, at first i thought the firewalls stopped sending logs , but it was not the case , i even launched the tcpdump command on the VM hosting splunk , and i see that the logs arrives , but when i search on splunk , i cannot find anything. If you have any idea please or you could suggest any ideas , I would appreciate your help. I m using splunk entrprise 10.0.0 hosted on ubuntu 22.04. Also i do not have any shortage when it comes to resources. Thank you for your time
... View more