Hi all.
We have several apps and indexes in Splunk. Suddenly, this morning, there were not data at any index (except indexes like _internal, _audit). By investigating we have seen that the majority of the indexes are disabled and because of this we have discovered that there was duplicated IDs of buckets (I don't know why). Searching in Splunk answers I have found how to fix the issue with duplicated bucket IDs (link text and I have follow these steps, hoping find data in the indexes after restart Splunk, but indexes does not have any data :(.
In the indexes view, there is some indexes that I can not enable (I don't know why), and the indexes that I can enable shows 0 Current Size. We have review the directory where the buckets are and there is data inside, because of this I don't know why searchs don't return any data.
We have also tried to upload new data to one index after enable it, and it seems to do it right in the "Add data" view, but when we finish the upload and select "Start search" it does not return any data. We have tried to create a new index and upload data into it, and it does not works. The index is created and it seems to upload data in it but when we search it does not returns any data, because the index is created disabled, how is it possible?
We have a big problem because no application is working 😞 I have been all day trying to get a solution, but really I don't know what is happening!!!
Thanks, thanks and thanks again.
... View more