Getting Data In

Why does my sourcetype= search return no results, but pairing with index= does?

craigkleen
Communicator

I re-did some of my data inputs using the same indexes as before to add actual sourcetypes this time. I'm using HWF instead of UF to send data to my indexer. I can now search "index=my_index sourcetype=my_sourcetype", but when my search is just "sourcetype=my_sourcetype", it returns no results over the same time period. Is there a way to fix that? It happened with a couple of sourcetypes, but not all of them.

Tags (2)
1 Solution

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

View solution in original post

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

craigkleen
Communicator

Yeah, that's it. Thanks!

0 Karma

acharlieh
Influencer

If I had to guess, the sourcetypes that return results are not returning results from my_index, but rather from other indexes? (check out the interesting fields)

Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...