I have a Json formatted log. Splunk shows my fields just fine. If I click one of my fields to filter by that field, Splunk copies my values into the search box. Suddenly today, this search returns zero results.
How do I start debugging this?
Use the Job Inspector
If your search returns an error you'll see this
If you don't get an error, you can get to the job inspector from the Job menu dropdown:
Then scroll down to messages and you'll find information on debugging.