Deployment Architecture

Splunk index on a Windows log folder

neltonk
Path Finder

New to Splunk please help...

I have created an index in Splunk enterprise and added a monitor to the splunk universal forwarder on a Windows Server. The size of the folder is 5 GB. I can see the index size growing but I am unable to search any data. Does the search work only after the index is fully populated?

Thanks

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

No, it does not! you can search for the data while you are indexing the data.

Efficient way to search for your data is

index=<name of the index>

Run this search for all time.
Also, if you do not have specified the name of the index then the default index name is main

let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

No, it does not! you can search for the data while you are indexing the data.

Efficient way to search for your data is

index=<name of the index>

Run this search for all time.
Also, if you do not have specified the name of the index then the default index name is main

let me know if this helps!

0 Karma

neltonk
Path Finder

Thanks a lot Mayur. That worked... Thanks again for the tip.

0 Karma

cmerriman
Super Champion

what exactly does your search look like? do you have the name of the index in your search string?
if you go into Settings>Users and Authentication Access Controls>Roles and click on your role, is the Windows Server index selected (or All internal/non-internal indexes)?

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...