<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Troubleshhoting in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624513#M78158</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no problem, tell me if I can help you more on this issue, otherwise, if one answer solves your need, please accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the Contributors;-)&lt;/P&gt;</description>
    <pubDate>Fri, 16 Dec 2022 07:35:03 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-12-16T07:35:03Z</dc:date>
    <item>
      <title>Why am I unable to retrieve events when searching with index=* ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624319#M78141</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1 - Search Head, 2-Indexers, 1 - Deployment Server, 1 - Heavy Forwarder, 1 -Cluster Master&lt;/P&gt;
&lt;P&gt;Problem Statement&lt;/P&gt;
&lt;P&gt;1)I am unable to retrieve events when searching with index=*&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 2) When checked with connectives all were connected (SH --&amp;gt; Indexers --&amp;gt; CM --&amp;gt; HF --&amp;gt; DS)&lt;/P&gt;
&lt;P&gt;When checked with internal index showing 401 client is not authenticated.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_0-1671089996297.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23006i5E1F96F1F27ED5E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_0-1671089996297.png" alt="Atchyuth_P_0-1671089996297.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When checked from backend there is no error showing in splunkd.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 09:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624319#M78141</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-12-15T09:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624321#M78142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you speaking of searches on SH or on IDXs?&lt;/P&gt;&lt;P&gt;if you have an IDXs Cluster, you cannot use them for searching only SH.&lt;/P&gt;&lt;P&gt;The other systems cannot be used for searching, only SH.&lt;/P&gt;&lt;P&gt;for using other systems for searching, you have to configurate them as SH.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 07:54:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624321#M78142</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T07:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624390#M78145</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, i found the mistake that i have done but from HF the data is not pushing to indexers.&lt;/P&gt;&lt;P&gt;I am sharing the screenshots for reference&lt;/P&gt;&lt;P&gt;&lt;U&gt;Heavy Forwarder :&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;inputs.conf&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_0-1671116120300.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23017iCFB23A9CCDCE8391/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_0-1671116120300.png" alt="Atchyuth_P_0-1671116120300.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;outputs.conf&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_1-1671116509716.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23018i8EEFC5AB6CEAB87F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_1-1671116509716.png" alt="Atchyuth_P_1-1671116509716.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Indexer 1&lt;/U&gt;&lt;/P&gt;&lt;P&gt;inputs.conf&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_2-1671116571052.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23019i688001429ECAC322/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_2-1671116571052.png" alt="Atchyuth_P_2-1671116571052.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_4-1671116708988.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23021iDE9F37E2AE6B3D6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_4-1671116708988.png" alt="Atchyuth_P_4-1671116708988.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Indexer 2&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_3-1671116631353.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23020i03E998539CA11795/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_3-1671116631353.png" alt="Atchyuth_P_3-1671116631353.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_4-1671116708988.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23021iDE9F37E2AE6B3D6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_4-1671116708988.png" alt="Atchyuth_P_4-1671116708988.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When i check with connectivity all were connected&lt;/P&gt;&lt;P&gt;The index is showing "0" Events&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_5-1671116952618.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23022iC5D174A6CCF154EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_5-1671116952618.png" alt="Atchyuth_P_5-1671116952618.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In HF i can see the data&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_6-1671116984116.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23023iF74B17D47D940FB4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_6-1671116984116.png" alt="Atchyuth_P_6-1671116984116.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624390#M78145</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-12-15T15:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624393#M78146</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;wher do you runned the search with results?&lt;/P&gt;&lt;P&gt;if you see data in HF, there something wrong in your configuration because there are two choices:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have a local copy of data,&lt;/LI&gt;&lt;LI&gt;you configured your HF as SH,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in both cases it isn't correct.&lt;/P&gt;&lt;P&gt;As I said: where do you runned the search with 0 results?&lt;/P&gt;&lt;P&gt;If in Indexer, it's correct because you cannot use Indexers for searching only SH.&lt;/P&gt;&lt;P&gt;If in SH you have to debug: are other searches running on SH (e.g. index=_internal)?&lt;/P&gt;&lt;P&gt;Configurations seems to be ok.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624393#M78146</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T15:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624395#M78147</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_0-1671118405855.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23024iBB6101B409D232CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_0-1671118405855.png" alt="Atchyuth_P_0-1671118405855.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I can see for HF to Indexer 2 the connection is in TIME_WAIT and for indexer 1 it is established&lt;/P&gt;&lt;P&gt;Yes there is a local copy but when i tried to check previously it worked the events got shown in indexer 2 but not in indexer 1&lt;/P&gt;&lt;P&gt;Now the data is not showing in two indexers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624395#M78147</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-12-15T15:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624398#M78148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;outputs.conf seems to be corrects, did you checked the connection between HF and IDX2 (if not try using telnet not ping)?&lt;/P&gt;&lt;P&gt;About local copy you shouldn't have it also because you have in your outputs.conf&amp;nbsp; "indexAndForward = false"&lt;/P&gt;&lt;P&gt;I repeat the question: where are you running searches: on SH or on another system?&lt;/P&gt;&lt;P&gt;How do you configured SH to search on IDXs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:47:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624398#M78148</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T15:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624402#M78149</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to check the search in both the indexers because the events is showing zero&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_1-1671120331674.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23026i7F45B01029F95DED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_1-1671120331674.png" alt="Atchyuth_P_1-1671120331674.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried both telnet and ping HF---&amp;gt; IDX2,IDX2 ---&amp;gt; HF all the connection established&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 16:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624402#M78149</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-12-15T16:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624403#M78150</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ping isn't relevant to check connections, uso only telnet on port 9997.&lt;/P&gt;&lt;P&gt;About searches: you cannot use Indexers (when clustered) for searching only Search Heads.&lt;/P&gt;&lt;P&gt;If search runs on a IDX means that there's a misconfiguration in the cluster.&lt;/P&gt;&lt;P&gt;What does it happen running a search a different index (obviously on SH)?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 16:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624403#M78150</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-15T16:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624412#M78152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the info i miss the catch i have done the configuration in SH as well. Almost, forgot IDX will not acts as SH.&lt;/P&gt;&lt;P&gt;Sorry for the trouble.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 16:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624412#M78152</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-12-15T16:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624513#M78158</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no problem, tell me if I can help you more on this issue, otherwise, if one answer solves your need, please accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the Contributors;-)&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 07:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624513#M78158</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-16T07:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Troubleshhoting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624553#M78163</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 13:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-unable-to-retrieve-events-when-searching-with-index/m-p/624553#M78163</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-16T13:59:32Z</dc:date>
    </item>
  </channel>
</rss>

