Hi,
Just now installed splunk.6.6 on Windows10 and loggedin. Uninstalled it.
installed again with new location for SPLUNK_HOME to c:\splunk\
Installation is successful, created a new user, changed password search query index=_internal sourcetype=splunkd says no results.
tried with index=* , again no results.
time window changed to 24 hours by default, instead of All time.
Regards,
Lakshmi K
Hi,
https://answers.splunk.com/answers/335162/how-do-i-troubleshoot-why-splunk-has-stopped-index.html
Mus answered this
in
htheretp://localhost:8000/en-US/manager/search/apps/local
forward enabled. Disabled it. Restarted splunk.
Issue resolved
http://localhost:8000/en-US/manager/search/apps/local
SplunkForwarder
SplunkLightForwarder
enabled.
As its my local installation, I moved the local folder from C:\Splunk\etc\apps\SplunkForwarder\ away, restarted splunk. Started working.
Mus anwered earlier
this is an usual one. the _internal index gets data later.
trying adding some sample data / log files, the tutorial data (http://www.splunk.com/base/images/Tutorial/Sampledata.zip) .. then internal index will get data.