<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I can't see my data in Security</title>
    <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127031#M14526</link>
    <description>&lt;P&gt;Thank you a lot&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2014 07:39:41 GMT</pubDate>
    <dc:creator>Yann_T</dc:creator>
    <dc:date>2014-04-17T07:39:41Z</dc:date>
    <item>
      <title>I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127016#M14511</link>
      <description>&lt;P&gt;I have installed splunk with an smtp apps.&lt;BR /&gt;
While a few moments everythings was ok.&lt;BR /&gt;
But since 7 days I can't see my data. The only thing I did was activate my new lincense. But it was about 6 days before today.&lt;BR /&gt;
My data are stored in a specific index but I'm far from the max size limit.&lt;BR /&gt;
What could be happened ? &lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 09:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127016#M14511</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-10T09:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127017#M14512</link>
      <description>&lt;P&gt;You probably need to provide more detail of the search you are using.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 10:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127017#M14512</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-04-10T10:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127018#M14513</link>
      <description>&lt;P&gt;What platform are you running on? (Windows, version/Linux, distro)&lt;/P&gt;

&lt;P&gt;What is the search string you are using?&lt;/P&gt;

&lt;P&gt;What do you see in ${SPLUNK_HOME}/var/log/splunk/splunkd.log and ${SPLUNK_HOME}/var/log/splunk/web_access.log&lt;/P&gt;

&lt;P&gt;Checking your licence (or license if you are American), are the details correct?&lt;BR /&gt;
  Manager -&amp;gt; Licensing&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:21:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127018#M14513</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2020-09-28T16:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127019#M14514</link>
      <description>&lt;P&gt;Grab a copy of the SoS app for debugging: &lt;A href="http://apps.splunk.com/app/748/"&gt;http://apps.splunk.com/app/748/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 13:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127019#M14514</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-10T13:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127020#M14515</link>
      <description>&lt;P&gt;I am running a linux platform "centOs 6"&lt;/P&gt;

&lt;P&gt;I just used "*" as search string in last 24 hours.&lt;/P&gt;

&lt;P&gt;On the start page of my own apps I can see 2,527,605 Events INDEXED and LATEST EVENT : 7 days ago.&lt;/P&gt;

&lt;P&gt;In my splunkd.log I have some errors notified many times&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;splunkd.log :&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;03-26-2014 13:07:38.038 +0100 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py" No SNMP response received before timeout snmp_stanza:snmp://snmp_user_ssid snmp_destination:10.1.1.250 snmp_port:161&lt;/P&gt;

&lt;P&gt;03-27-2014 11:06:14.625 +0100 WARN  ExecProcessor - Streaming XML data: Received an event with missing or empty "data" tag.&lt;/P&gt;

&lt;P&gt;03-27-2014 12:09:41.981 +0100 ERROR databasePartitionPolicy - insufficient privileges to perform this operation&lt;BR /&gt;
03-27-2014 12:09:42.588 +0100 ERROR StreamingDeleteOperator - Error in 'delete' command: You have insufficient privileges to delete events.&lt;/P&gt;

&lt;P&gt;04-09-2014 23:23:11.925 +0200 WARN  DateParserVerbose - A possible timestamp match (Tue May 10 10:20:57 2005) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source::snmp://userRxData|host::10.1.1.250|logsnmp_userRxData|0&lt;/P&gt;

&lt;P&gt;And for my licence  all details are correct (I'm french)&lt;/P&gt;

&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127020#M14515</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2020-09-28T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127021#M14516</link>
      <description>&lt;P&gt;I installed SoS app but how can it help me ? I don't see anything wrong at this time.&lt;BR /&gt;
But I can see some errors in my logs&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 14:11:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127021#M14516</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-10T14:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127022#M14517</link>
      <description>&lt;P&gt;Those errors could be telling you something about what's going wrong.&lt;/P&gt;

&lt;P&gt;The beauty of SoS is that you can see at a glance what amount of data is going where at what point in time, without having to crawl through the &lt;CODE&gt;_internal&lt;/CODE&gt; index yourself.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 14:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127022#M14517</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-10T14:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127023#M14518</link>
      <description>&lt;P&gt;I have the ERROR : tcpinputproc : could not bind to port IPV4 port 80 &lt;/P&gt;

&lt;P&gt;do you know what is it ?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 15:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127023#M14518</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-10T15:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127024#M14519</link>
      <description>&lt;P&gt;Sounds like you're trying to tell Splunk to listen to data coming in on port 80, but binding to that port failed. Common reasons are either lack of permissions due to not being run as root, or already bound ports due to in this case an existing HTTP server.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 16:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127024#M14519</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-10T16:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127025#M14520</link>
      <description>&lt;P&gt;how can I see what's going wrong with SoS ? I can see a lot of things but for example I can't see anything in "Warnings and errors"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 14:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127025#M14520</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-11T14:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127026#M14521</link>
      <description>&lt;P&gt;The indexing views can tell you if anything is being indexed, and into what index, to confirm if anything is coming in or not.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 15:10:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127026#M14521</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-11T15:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127027#M14522</link>
      <description>&lt;P&gt;Ok so I can see that I have events in my indexer.&lt;BR /&gt;
But when I try to catch out them with a simple "*" I don't have anything&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 15:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127027#M14522</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-11T15:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127028#M14523</link>
      <description>&lt;P&gt;Add a filter like &lt;CODE&gt;index=thatindex&lt;/CODE&gt;. Depending on your user's role you're only searching some indexes by default.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 15:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127028#M14523</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-11T15:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127029#M14524</link>
      <description>&lt;P&gt;Thank you when I add a filter I have my data. But I always see in the main page LAST EVENT :  8 days ago ?&lt;BR /&gt;
I don't know why&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 15:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127029#M14524</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-11T15:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127030#M14525</link>
      <description>&lt;P&gt;The problem appears to be that your user's role isn't searching the relevant indexes by default - then the display at the start will not see those events.&lt;/P&gt;

&lt;P&gt;Edit your user's role to search all non-internal indexes by default if you want to change that, just remember that a search for "foo" will then search through all indexes.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 15:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127030#M14525</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-11T15:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127031#M14526</link>
      <description>&lt;P&gt;Thank you a lot&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 07:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127031#M14526</guid>
      <dc:creator>Yann_T</dc:creator>
      <dc:date>2014-04-17T07:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: I can't see my data</title>
      <link>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127032#M14527</link>
      <description>&lt;P&gt;Can you please tell me how to edit user's role to search all non-internal indexes?&lt;BR /&gt;
@martin_mueller  &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/139049"&gt;@Yann_T&lt;/a&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/I-can-t-see-my-data/m-p/127032#M14527</guid>
      <dc:creator>mycloudsplunk</dc:creator>
      <dc:date>2020-09-30T01:21:36Z</dc:date>
    </item>
  </channel>
</rss>

