<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard message &amp;quot;Search did not return any events&amp;quot; in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647416#M79301</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am very sorry and figured out what my issue was, the panel appeared to have switched to events instead of a statistics table! Thanks for reaching out to help!&lt;/P&gt;</description>
    <pubDate>Sun, 18 Jun 2023 06:39:05 GMT</pubDate>
    <dc:creator>ajones</dc:creator>
    <dc:date>2023-06-18T06:39:05Z</dc:date>
    <item>
      <title>Why did search did not return any events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544518#M65194</link>
      <description>&lt;P&gt;I'm working on a dashboard that is not returning any results but can find events upon clicking the "Open in Search" link.&amp;nbsp; Why is it not showing results on the dashboard view?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-03-19 094615.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13392iCAD5BD280AA1758C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-03-19 094615.jpg" alt="Screenshot 2021-03-19 094615.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 15:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544518#M65194</guid>
      <dc:creator>mwestley</dc:creator>
      <dc:date>2023-06-19T15:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544521#M65195</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232052"&gt;@mwestley&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The search is returning results when your time range is selected as All time.&amp;nbsp; So Add a time range filter in the dashboard and check for the results.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544521#M65195</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-19T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544793#M65200</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I was hopeful trying your suggestion but after adding the time range picker still am getting no results.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; I am curious though on the Search results page where it shows statistics of 64 but events is zero.&amp;nbsp; Why is that?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-03-22 102818.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13431i4D585E99C86F4997/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-03-22 102818.jpg" alt="Screenshot 2021-03-22 102818.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 15:29:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544793#M65200</guid>
      <dc:creator>mwestley</dc:creator>
      <dc:date>2021-03-22T15:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544798#M65201</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mwestley_0-1616427476768.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13434iF7D4790543E1F1E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mwestley_0-1616427476768.png" alt="mwestley_0-1616427476768.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 15:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544798#M65201</guid>
      <dc:creator>mwestley</dc:creator>
      <dc:date>2021-03-22T15:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544809#M65202</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232052"&gt;@mwestley&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you select the time range as the Previous year and check for the result?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vardhan_0-1616433518874.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13435iF6964C969A72F2E2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Vardhan_0-1616433518874.png" alt="Vardhan_0-1616433518874.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And also after creating a time range input did you applied the time range on the search?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vardhan_0-1616433737471.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13436iB4CF971E34D8E7FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Vardhan_0-1616433737471.png" alt="Vardhan_0-1616433737471.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vardhan_1-1616433788874.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13437i7F8615C2D2BD4A0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Vardhan_1-1616433788874.png" alt="Vardhan_1-1616433788874.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 17:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/544809#M65202</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-22T17:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647411#M79298</link>
      <description>&lt;P&gt;Has this problem been figured out yet? I am having the same issue now and am unable to figure out what is going on. Thank you!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 04:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647411#M79298</guid>
      <dc:creator>ajones</dc:creator>
      <dc:date>2023-06-18T04:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647413#M79299</link>
      <description>&lt;P&gt;Please share your dashboard source code in a code block &amp;lt;/&amp;gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 05:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647413#M79299</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-18T05:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647414#M79300</link>
      <description>&lt;LI-CODE lang="markup"&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;[REDACTED]&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="time" token="timerange" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Time Range&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-2w@w&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;[REDACTED]&amp;lt;/title&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;title&amp;gt;[REDACTED]&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| inputlookup [REDACTED].csv | bucket _time span=1week | addinfo | eval WeekA=strftime(info_min_time, "%V") | eval WeekB=strftime(info_max_time, "%V") | where [REDACTED] == [REDACTED] AND refwoy &amp;amp;gt;= WeekA AND refwoy &amp;amp;lt; WeekB | eval f_time=strftime(refdate, "%Y-%m-%d") | xyseries [REDACTED] f_time count | foreach * [| eval total=if(isnull(total),0,total) | eval total=total+1| eval DIFF=if(total=1, -1* '&amp;amp;lt;&amp;amp;lt;FIELD&amp;amp;gt;&amp;amp;gt;', DIFF + '&amp;amp;lt;&amp;amp;lt;FIELD&amp;amp;gt;&amp;amp;gt;')] | eval temp=split(DIFF,"http") | eval Difference=mvindex(temp,0) | fields - total, temp, DIFF&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timerange.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timerange.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="list.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;[REDACTED]&amp;lt;/title&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;title&amp;gt;[REDACTED]&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| inputlookup [REDACTED].csv | bucket _time span=1week | addinfo | eval WeekA=strftime(info_min_time, "%V") | eval WeekB=strftime(info_max_time, "%V") | where [REDACTED] == [REDACTED] AND refwoy &amp;amp;gt;= WeekA AND refwoy &amp;amp;lt; WeekB | eval f_time=strftime(refdate, "%Y-%m-%d") | xyseries [REDACTED] f_time count | foreach * [| eval total=if(isnull(total),0,total) | eval total=total+1| eval DIFF=if(total=1, -1* '&amp;amp;lt;&amp;amp;lt;FIELD&amp;amp;gt;&amp;amp;gt;', DIFF + '&amp;amp;lt;&amp;amp;lt;FIELD&amp;amp;gt;&amp;amp;gt;')] | eval temp=split(DIFF,"http") | eval Difference=mvindex(temp,0) | fields - total, temp, DIFF&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timerange.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timerange.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="list.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 18 Jun 2023 06:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647414#M79300</guid>
      <dc:creator>ajones</dc:creator>
      <dc:date>2023-06-18T06:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647416#M79301</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am very sorry and figured out what my issue was, the panel appeared to have switched to events instead of a statistics table! Thanks for reaching out to help!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 06:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647416#M79301</guid>
      <dc:creator>ajones</dc:creator>
      <dc:date>2023-06-18T06:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard message "Search did not return any events"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647417#M79302</link>
      <description>&lt;P&gt;No worries&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257848"&gt;@ajones&lt;/a&gt;&amp;nbsp;- you were hijacking&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232052"&gt;@mwestley&lt;/a&gt;&amp;nbsp;post anyway. Glad you got your issue sorted out though.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 06:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-search-did-not-return-any-events/m-p/647417#M79302</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-18T06:58:42Z</dc:date>
    </item>
  </channel>
</rss>

