Having access to _internal does not mean you have access to all other indexes. Check with your Splunk admin to see if your role is allowed to access index abc.
@richgalloway , i do have access for the index=abc don't know why data is not coming into that host , while checking in backend able to see logs coming on daily basis , but it is not ingesting in index=abc .
While in backend am able to follow this path /home/sv_cidm/files and able to see logs
what should I do know , please help your help will be appreciated .
Thanks
If it's just that host that is affected then verify the input for that file is present on the host and not disabled. Make sure Splunk still has read access to the file. Check splunkd.log on the host for any messages that might explain the problem.
Hi
you should tell more about your situation like
Without this kind of base information it's quite frustrating to guess what the reason could be!
There are also quite many similar issues already solved in community. Just try to use google/bing/what ever your search engine is, to see how these are normally solved.
r. Ismo