<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search area not giving me output when used in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645171#M16472</link>
    <description>&lt;P&gt;If you are an admin then you should have access to _internal.&amp;nbsp; Try searching &lt;FONT face="courier new,courier"&gt;index=_internal earliest=-1h&lt;/FONT&gt;.&amp;nbsp; If you get results then you have access.&lt;/P&gt;&lt;P&gt;Another way is to go to Settings-&amp;gt;Users and look at your account.&lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2023 01:50:25 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-05-31T01:50:25Z</dc:date>
    <item>
      <title>Why is search area not giving me output when used?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644777#M16452</link>
      <description>&lt;P&gt;I have a splunk acct that i login to via vpn. The issue is that when i use the "search" area i cannot get an output but i when i use the "find" area for the same query, i get my output. Is there a way the change that? I just want to put my query in the "search" area to get my output.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 03:16:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644777#M16452</guid>
      <dc:creator>ludjunior</dc:creator>
      <dc:date>2023-05-31T03:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644786#M16453</link>
      <description>&lt;P&gt;Welcome to Splunk!&lt;/P&gt;&lt;P&gt;Please help us to help you.&amp;nbsp; What do you mean by "search area" and "find area"?&amp;nbsp; What text are you putting into each?&amp;nbsp; What are you trying to get for output?&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 20:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644786#M16453</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-26T20:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644791#M16454</link>
      <description>&lt;P&gt;In the search, if I put index=“_internal” I won’t get anything but if I go on the top right corner and put the same query I will get an output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 20:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644791#M16454</guid>
      <dc:creator>ludjunior</dc:creator>
      <dc:date>2023-05-26T20:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644801#M16455</link>
      <description>&lt;P&gt;If you put "index=_internal" in the Find box then you should get a list of reports and dashboards that contain that string.&amp;nbsp; The last entry should be "Open 'index=_internal' in Search.&amp;nbsp; Clicking that should be the same as putting "index=_internal" in a search box.&lt;/P&gt;&lt;P&gt;Do you have access to the _internal index?&amp;nbsp; Usually, only admins and (sometimes) power users have access.&amp;nbsp; Not having access to the index would explain why you get no results from the Search box (no, Splunk won't say "you don't have access").&amp;nbsp; OTOH, if the Find box turns up a report that runs as&amp;nbsp; Owner and the owner has access then you will see results.&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2023 00:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/644801#M16455</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-27T00:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645169#M16471</link>
      <description>&lt;P&gt;Hi Richgalloway,&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, I am one of the admins on the acct. I have to find out whether I have access to the index. How would i find out?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 00:18:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645169#M16471</guid>
      <dc:creator>ludjunior</dc:creator>
      <dc:date>2023-05-31T00:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645171#M16472</link>
      <description>&lt;P&gt;If you are an admin then you should have access to _internal.&amp;nbsp; Try searching &lt;FONT face="courier new,courier"&gt;index=_internal earliest=-1h&lt;/FONT&gt;.&amp;nbsp; If you get results then you have access.&lt;/P&gt;&lt;P&gt;Another way is to go to Settings-&amp;gt;Users and look at your account.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 01:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645171#M16472</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-31T01:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645791#M16503</link>
      <description>&lt;P&gt;I checked my acct again. I am admin, can_delete, power, Splunk-system-role, user&lt;/P&gt;&lt;P&gt;Do you think it's the VPN link that I'm using to get to Splunk?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 16:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/645791#M16503</guid>
      <dc:creator>ludjunior</dc:creator>
      <dc:date>2023-06-05T16:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: search area not giving me output when used</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/646652#M16560</link>
      <description>&lt;P&gt;In addition to looking at your capabilities, look at the indexes you are allowed to access.&amp;nbsp; Do that by going to Settings-&amp;gt;Roles and clicking on your role.&amp;nbsp; Then select the Indexes tab.&amp;nbsp; There should be a mark in the _internal box.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 12:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-search-area-not-giving-me-output-when-used/m-p/646652#M16560</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-12T12:51:49Z</dc:date>
    </item>
  </channel>
</rss>

