Splunk Search

New index mapped to Hdfs data input does not result -only main index shows data

deepakmurthy
Explorer

Hi Folks,

Sorry for a basic question, I am a newbie.

I have successfully installed and configured Hadoop Connect to Splunk.

  • Created a HDFS input, selected default in my index selection (Index test_stage was not created)

  • Went to my search field and entered my sourcetype resulted the event data and was showing index as main

  • After the above step, i created a new index test_stage, went to Hadoop Connect HDFS and changed my index to test_stage.

  • Reloaded index and Restarted splunk still my index does not show any results.

  • Main index shows all the data, test_stage says "No results found"

Here is the cat inputs.conf
[hdfs://x.x.x.x/user/test/stage/test_stage]
host = test_stage
sourcetype = test_XML
index = test_stage

inputs.conf shows right index, why i am still not seeing any data in my new index?

PS: I also verified roles for admin user has access to search this index.

Please suggest me where I am doing wrong and any solutions.

Thanks for looking into this question.

Tags (3)
0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

please specify your search.

Do you use

index=test_stage | head 10

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...