Getting Data In

Why does my sourcetype= search return no results, but pairing with index= does?

craigkleen
Communicator

I re-did some of my data inputs using the same indexes as before to add actual sourcetypes this time. I'm using HWF instead of UF to send data to my indexer. I can now search "index=my_index sourcetype=my_sourcetype", but when my search is just "sourcetype=my_sourcetype", it returns no results over the same time period. Is there a way to fix that? It happened with a couple of sourcetypes, but not all of them.

Tags (2)
1 Solution

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

View solution in original post

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

craigkleen
Communicator

Yeah, that's it. Thanks!

0 Karma

acharlieh
Influencer

If I had to guess, the sourcetypes that return results are not returning results from my_index, but rather from other indexes? (check out the interesting fields)

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...