Getting Data In

Data upload from splunk ui is successful, but data is not appearing in search

jagdish0886
Explorer

Hi,
I have uploaded the data to splunk, but while searching the data doesnt appear, I have shared the screenshots as well. Can you please help here.
Index used - default
log file type - .log
search criteria - all time
Splunk version of docker - store/splunk/splunk:7.3

alt text

0 Karma
1 Solution

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

View solution in original post

0 Karma

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

0 Karma

jagdish0886
Explorer

adding few more details:
When I upload the data from Splunk UI, it notifies that data is successfully uploaded, however
indexed data doesn't reflect in Splunk indexed data path opt/splunk/var/lib/splunk/spice-index/db and hence not searchable from splunk UI. Please help how to make the data searchable:

Index used: default and custom (both same issue)
search criteria: all time
splunk docker container: version store/splunk/splunk:7.3  developer licence
file size : 500 KB file type .log
browser: tried with chrome and IE
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...