Splunk Search

An index is shown under default search for a role, but why is a search on this index producing "No result" on the search head?

u192612
New Member

Hello Team,

xyz_prd_index created, running forwarder fine on the host. It displays all indexers too when we do listforward with the manage script. Also In role/user, showing this index under default search. But not showing any indexed data for this index in search head..it showing "no result".
Also restricted this index under role too like (index=xyz_prd_index)..

Appreciate if you can assist here ..

Thanks,

0 Karma

sundareshr
Legend

What timerange you searching? Try alltime

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I think I understand what your asking, you want to know why the data from your remote host isn't available in the Splunk GUI when searching for it right?

So my question is, how do you know the forwarder is forwarding the data? Did you define the xyz_prd_index in your inputs.conf on your forwarder? Is this a new index?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...