Deployment Architecture

Why do I not see data from an index after restart?

power12
Communicator

Hello SPlunkers ,

 

I am not seeing data for a particular index after restart

3/29/23
5:00:34.647 PM
03-30-2023 00:00:34.647 +0000 INFO HotDBManager [7073 indexerPipe] - closing hot mgr for idx=abc
component = HotDBManagerhost = abc index = _internalsource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.618 PM
03-30-2023 00:00:34.618 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Handling shutdown or signal, reason=1
component = IndexWriterhost = abc index = _internals ource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.601 PM
03-30-2023 00:00:34.601 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Sync before shutdown

Restarted splunk again and then enabled and disabled the index but still not seeing data...checked source..it is showing data

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify you still have permission to access to the index.

Make sure the indexes.conf settings for the index did not change.

Confirm data is still being forwarded from the source to Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...