Getting Data In

replaced with new index with old one in inputs.conf

sathwikr076
Communicator

I have changed the index name for a log ingestion to a new one but the logs are still ingesting to the old index. I cannot understand why the logs are not ingesting to new index. Please let me know if anyone have any idea.

Thanks.

0 Karma

jacobpevans
Motivator

Greetings @sathwikr076,

  1. Does the index exist on the indexer that the data is being forwarded to?
  2. Did you restart the Splunk forwarder service on the machine that is monitoring the log?

Cheers,
Jacob

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

sathwikr076
Communicator

Thanks for the response. Yes, the new index exist on all the indexers and i have restarted the forwarder. checked if the index name has changed on the server by the application team and it has the new index in the inputs.conf but still it is ingesting to the old index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sathwikr076,
how do you changed destination index?

  • in inputs.conf on Universal Forwarders,
  • in overriding on Indexers?

If on UFs, after update, did you restarted Splunk on UFs?
If on Indexers, after update, did you restarted Splunk on Indexers? have you in the middle any Heavy Forwarders?

Bye.
Giuseppe

0 Karma

sathwikr076
Communicator

i have changed on UF and restarted the service through deployment server remotely as i do not have access to the server. i checked the internal logs and i can see
Metrics - group=per_index_thruput, series="new_index", kbps=0.22774524335479657, eps=0.19367014189230036, kb=7.0556640625, ev=6, avg_age=9110.833333333334, max_age=54545 but still it is ingesting to the old index. i just asked the application team to restart the forwarder directly on the server.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...