Getting Data In

DATA not feeding in INDEX : Splunk

vivekg72
Explorer

Hi

I have got 5 node SPLUNK .

NODE1 : Master + License Manager
Node 2 : Indexer - peer
Node 3 : Indexer - Peer
Node 4 : Indexer - Peer
Node 5 : Search head

All is working fine . Now I need to create a new index for test purpose . and push one file in that index

Thus I have done following :

In master Node , We have a file called indexes.conf under :
/apps/splunk/etc/master-apps/app-infrastructure-loganalysis/local

I have added a few index lines :
[indexwinelksynclogs]
homePath = /data/splunk/indexwinelksynclogs/db
coldPath = /data/splunk/indexwinelksynclogs/colddb
thawedPath = /data/splunk/indexwinelksynclogs/thaweddb
repFactor = auto

0 Karma

vivekg72
Explorer

Therefter I did following in master :

splunk apply cluster-bundle
splunk show cluster-bundle-status

I can see new index file is deployed in All Index servers . I have restarted whole cluster
and I can see index in UI

but When I try to push data , it does not work .. nothing goes in index

Can u please help me ASAP ?

0 Karma

vivekg72
Explorer

Hi

I have added following lines in input.conf of splunk forwarder

[monitor://D:\PTP\Daily*.csv]
disabled = false
sourcetype = indexwinelksynclogs
index = indexwinelksynclogs

0 Karma

vivekg72
Explorer

There are two more stanza in input file ( using old indexes ) and I can see data in those indexes updated regularly

but not in new Index .

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please say more about how you are pushing data and how you are searching for it. How are you specifying the index name? Are you specifying the correct index?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...