Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Data loss after shutdown Splunk

$
0
0
Hi, I used "Add Data: Files and Directories" function to add a 200MB csv file from my hard drive into Splunk Enterprise 8.0.2 (Trial Version, MacOS). In order to do that, I configured it with a custom sourcetype and a custom index called "bigdbook". As the result, the file was uploaded successfully. I checked again by looking in the Settings > Data: Indexes section and saw an increment at the value of the current size column, the value was 124MB. ![alt text][1] But after I shut down Splunk and started it back on, then I did several searches and found out that the data that I inputted was completely gone as the current size column's value in the indexes section returned to the default value 1MB. ![alt text][2] So far, I have tried reinstalling Splunk and switching to "Add Data: Monitor" but the problem remains the same. Please help me regarding this. [1]: /storage/temp/284610-screen-shot-2020-02-28-at-13957-pm.png [2]: /storage/temp/284611-screen-shot-2020-02-28-at-20007-pm.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>