<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data being indexed but unable to search in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56851#M11082</link>
    <description>&lt;P&gt;It is configured to forward to the "security" index.  It is using a heavy forwarder because that is what my system admin felt most comfortable installing.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2012 14:12:15 GMT</pubDate>
    <dc:creator>rmcdougal</dc:creator>
    <dc:date>2012-12-10T14:12:15Z</dc:date>
    <item>
      <title>Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56847#M11078</link>
      <description>&lt;P&gt;Ok so here is the issue, I have installed a forwarder on my Snort box to forward over the data to Splunk.  It appears to be sending the data over and it appears to be getting indexed but, I am not able to search the information.&lt;/P&gt;

&lt;P&gt;This is my search summary page&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/FRDvg.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Notice the last update time.&lt;/P&gt;

&lt;P&gt;Now I am going to click on the source type and search for the events.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/gaPVD.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Notice that the latest event showing up has a timestamp of 12/6/2012 at 12:56 AM.  This contradicts the search summary page.&lt;/P&gt;

&lt;P&gt;One last thing, from the deployment monitor, this is the status of the forwarder on my snort box.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/r9Hj5.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2012 20:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56847#M11078</guid>
      <dc:creator>rmcdougal</dc:creator>
      <dc:date>2012-12-06T20:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56848#M11079</link>
      <description>&lt;P&gt;What index does the forwarder specify for the snort data in inputs.conf?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 01:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56848#M11079</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-12-10T01:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56849#M11080</link>
      <description>&lt;P&gt;And, why 'Heavy Forwarder' and not 'Universal'?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 04:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56849#M11080</guid>
      <dc:creator>miteshvohra</dc:creator>
      <dc:date>2012-12-10T04:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56850#M11081</link>
      <description>&lt;P&gt;Also, if I recall correctly the time on the summary page is when the last event was INDEXED, not necessarily when it was actually generated.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 10:22:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56850#M11081</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-10T10:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56851#M11082</link>
      <description>&lt;P&gt;It is configured to forward to the "security" index.  It is using a heavy forwarder because that is what my system admin felt most comfortable installing.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 14:12:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56851#M11082</guid>
      <dc:creator>rmcdougal</dc:creator>
      <dc:date>2012-12-10T14:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56852#M11083</link>
      <description>&lt;P&gt;The summary page only displays data in the main index by default, so it won't register detail on other indexes.&lt;/P&gt;

&lt;P&gt;Related: &lt;A href="http://splunk-base.splunk.com/answers/47879/cannot-see-data-that-gets-indexed-on-summary-page"&gt;http://splunk-base.splunk.com/answers/47879/cannot-see-data-that-gets-indexed-on-summary-page&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 15:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56852#M11083</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-12-10T15:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56853#M11084</link>
      <description>&lt;P&gt;My guess is that your Splunk admin did NOT set up the security index to be searched by default. That setting is under Manager -&amp;gt; Access Control -&amp;gt; Roles. For each role, the admin can determine which indexes are visible and which indexes are searched by default.&lt;/P&gt;

&lt;P&gt;If the security index is NOT one of your default indexes, you may be able to search it explicitly:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=security sourcetype=snort
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that doesn't work, perhaps the Splunk admin has not given you access to the security index at all.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 22:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56853#M11084</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-12-10T22:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Data being indexed but unable to search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56854#M11085</link>
      <description>&lt;P&gt;I found the solution and it wasn't very intuitive.  The timestamp was not being indexed properly by splunk so the events were getting indexed but there was an invalid timestamp associated with them preventing them from showing when searching for them.  (I still haven't been able to find them).&lt;/P&gt;

&lt;P&gt;After changing the TIME_FORMAT in props.conf the events started to display.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 13:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-being-indexed-but-unable-to-search/m-p/56854#M11085</guid>
      <dc:creator>rmcdougal</dc:creator>
      <dc:date>2012-12-11T13:54:51Z</dc:date>
    </item>
  </channel>
</rss>

