Splunk Search

why is my search not returning any output ?

vmallipe
New Member

Hi There,

I'm pretty new to the splunk. we have 3 physical splunk servers and all the forweders are forwarding to 1 and 2. All of sudden some searchs stopped working and rest are working fine. Dont know where to start from. Any help is much appreciated.

Thanks in Advance.

Tags (1)
0 Karma

Takajian
Builder

Splunk internal log is logging in /$SPLUNK_HOME/var/log/splunk/splunkd.log. Please confirm if there is any error or crash.

0 Karma

mw
Splunk Employee
Splunk Employee

Have you tried running the searches which no longer work against a time frame where they were known to work to see if it's the search or the data?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...