Hi, I used "Add Data: Files and Directories" function to add a 200MB csv file from my hard drive into Splunk Enterprise 8.0.2 (Trial Version, MacOS). In order to do that, I configured it with a custom sourcetype and a custom index called "bigdbook".
As the result, the file was uploaded successfully. I checked again by looking in the Settings > Data: Indexes section and saw an increment at the value of the current size column, the value was 124MB.
![alt text][1]
But after I shut down Splunk and started it back on, then I did several searches and found out that the data that I inputted was completely gone as the current size column's value in the indexes section returned to the default value 1MB.
![alt text][2]
So far, I have tried reinstalling Splunk and switching to "Add Data: Monitor" but the problem remains the same.
Please help me regarding this.
[1]: /storage/temp/284610-screen-shot-2020-02-28-at-13957-pm.png
[2]: /storage/temp/284611-screen-shot-2020-02-28-at-20007-pm.png
↧