Splunk Enterprise

Why can I not see the data in Splunk UI?

Santosh2
Path Finder

Hi all, I can see the logs coming in from a particular source=das*.log through backend Linux but when I search with the same source I cannot see data in ui 

One more thing if I use with index name and source also I am not getting any data in ui 

Note: when I searched with internal index I could see logs from that host IP but not from the source in ui 

Can any one help on this issue.

 

 

Labels (1)
Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Santosh2 - You can take some predefined steps in case of data input issues:

  • Check if you have inputs.conf entry for these files
  • Have you specified the right index?
  • Have you created that index on the Indexer?
  • Make sure you are not filtering the data with transforms.conf config
    • check for queue=null line in transforms.conf 
    • If you see any, make sure it's not related to your data
  • Make sure you are receiving other data from that host.
    • index=_internal host=<hostname-that-has-inputs.conf> 
  • Make sure you have permission to read the index data and also make sure no other restriction being applied.
    • You can check with Splunk Admin.

 

I hope this helps!!! Upvote/karma would be appreciated!!

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...