Hello SPlunkers ,
I am not seeing data for a particular index after restart
3/29/23
5:00:34.647 PM
03-30-2023 00:00:34.647 +0000 INFO HotDBManager [7073 indexerPipe] - closing hot mgr for idx=abc
component = HotDBManagerhost = abc index = _internalsource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.618 PM
03-30-2023 00:00:34.618 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Handling shutdown or signal, reason=1
component = IndexWriterhost = abc index = _internals ource = /opt/splunk/var/log/splunk/splunkd.logsourcetype = splunkd
3/29/23
5:00:34.601 PM
03-30-2023 00:00:34.601 +0000 INFO IndexWriter [7073 indexerPipe] - idx=abc Sync before shutdown
Restarted splunk again and then enabled and disabled the index but still not seeing data...checked source..it is showing data
Verify you still have permission to access to the index.
Make sure the indexes.conf settings for the index did not change.
Confirm data is still being forwarded from the source to Splunk.