Splunk Search

i am unable to search the data with sourcetype name but i can search data by index name.

Utkarsh_Singh
New Member

i am unable to search the data with sourcetype name but i can search data by index name.Please tell what can i do to resolve this.

Tags (1)
0 Karma

493669
Super Champion

you must update your Role(s) to include that index as part of the "Indexes searched by default."
In UI, Go to

 Settings>>Access controles>>Roles>>Select specific role>>Scroll down to "Indexes searched by default">>include your index>>Click SAVE

It will update authorize.conf for specific role
and now you can search by sourcetype also.

0 Karma

harsmarvania57
Ultra Champion

It looks like you don't have index specified in srchIndexesDefault in authorize.conf for specific role, so in that case when you use index=abc you will able to search but when you type sourcetype=xyz it will try to search in indexes which is given in srchIndexesDefault. If you don't provide any index in srchIndexesDefault in authorize.conf for particular role then it will not display any result when you run sourcetype=xyz query.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...