Why does the search index=_internal
not return any results?
Please add the config to your local authorize.conf file to the one below, restart splunk and now try to search
srchIndexesAllowed = ;_
You can find more on this config in the link below
http://docs.splunk.com/Documentation/Splunk/6.0/admin/authorizeconf
Please add the config to your local authorize.conf file to the one below, restart splunk and now try to search
srchIndexesAllowed = ;_
You can find more on this config in the link below
http://docs.splunk.com/Documentation/Splunk/6.0/admin/authorizeconf