Ok so I ran command
splunk clean eventdata
And now my Splunk is not working as earlier. I am able to ADD log file/folder but its not showing anything in search even for any time frame.
I was seeing lots of Sources and one Host in
Search-> Data Summary
but not any more.
The command you ran would have deleted all the events in splunk. If you have existing inputs they will not reindex the data you have deleted unless you remove the relevant fishbucket entries. If you want to reindex everything then on your forwarder delete the directory $SPLUNK_HOME/var/lib/splunk/fishbucket
. To reindex a single file have a look at the documentation for btprobe https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSuppor...