Splunk Search

Its showing nothing in Splunk logs window for any kind of search

jaikratsingh
New Member

Ok so I ran command

splunk clean eventdata

And now my Splunk is not working as earlier. I am able to ADD log file/folder but its not showing anything in search even for any time frame.

I was seeing lots of Sources and one Host in

Search-> Data Summary

but not any more.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The command you ran would have deleted all the events in splunk. If you have existing inputs they will not reindex the data you have deleted unless you remove the relevant fishbucket entries. If you want to reindex everything then on your forwarder delete the directory $SPLUNK_HOME/var/lib/splunk/fishbucket. To reindex a single file have a look at the documentation for btprobe https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSuppor...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...