Splunk Search

Its showing nothing in Splunk logs window for any kind of search

jaikratsingh
New Member

Ok so I ran command

splunk clean eventdata

And now my Splunk is not working as earlier. I am able to ADD log file/folder but its not showing anything in search even for any time frame.

I was seeing lots of Sources and one Host in

Search-> Data Summary

but not any more.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The command you ran would have deleted all the events in splunk. If you have existing inputs they will not reindex the data you have deleted unless you remove the relevant fishbucket entries. If you want to reindex everything then on your forwarder delete the directory $SPLUNK_HOME/var/lib/splunk/fishbucket. To reindex a single file have a look at the documentation for btprobe https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSuppor...

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...