Splunk Search

I get results for metadata searches, but why do I get 0 search results running regular searches on my new Splunk 6.2.3 search head?

ltrand
Contributor

Hello Splunkverse,

I've recently set up a new Search Head to test 6.2.3 and it looks awesome. I do have one major issue however that I can't seem to figure out. When I do metadata searches, I can get results. When I use the new Deployment Console, everything is correct. However, when I try to do regular searches I always get 0 results, regardless of the indexes I search. Any thoughts as to what I might have missed in configuration? All indexers are on 6.1.3.

Thanks!

Tags (3)
0 Karma
1 Solution

woodcock
Esteemed Legend

Give us an example of a "regular search". I find it hard to believe that, if you have your peering correct, that you don't get results. Perhaps you are in the (very bad) habit of relying on "indexes searched by default" and maybe you have no data in index main. That would make searches like sourcetype=bar fail when a search like index=foo sourcetype=bar works.

View solution in original post

woodcock
Esteemed Legend

Give us an example of a "regular search". I find it hard to believe that, if you have your peering correct, that you don't get results. Perhaps you are in the (very bad) habit of relying on "indexes searched by default" and maybe you have no data in index main. That would make searches like sourcetype=bar fail when a search like index=foo sourcetype=bar works.

ltrand
Contributor

Thanks, I didn't realize the default admin was limited in searching!

0 Karma

woodcock
Esteemed Legend

You forgot to peer your new Search Head to your existing indexers: Settings -> Distributed search -> Search peers.

0 Karma

ltrand
Contributor

Thanks for the attempt. All indexers in my environment are listed as search peers for me and have a up status with successful replication.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...