<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to search using Sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185838#M37211</link>
    <description>&lt;P&gt;I have set up a indexer which I also use as an Search Head. I dont have a deployment server so I manually pushed (copied) the apps to the servers to configure the forwarders. The forwarders work just fine and are recognized by the Indexer. And the props as well as input apps work well. And I am able to search for the index data using:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="test_index"  sourcetype=test_sourcetype&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;All fields defined in props and transform file, show up correctly. These fields  also show correctly: host, source and sourcetype. I can see "sourcetype=test_sourcetype" in the events. But I am unable search events using:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;sourcetype=test_sourcetype&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Any help will be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Olavo&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 18:02:01 GMT</pubDate>
    <dc:creator>olavo123</dc:creator>
    <dc:date>2020-09-28T18:02:01Z</dc:date>
    <item>
      <title>Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185838#M37211</link>
      <description>&lt;P&gt;I have set up a indexer which I also use as an Search Head. I dont have a deployment server so I manually pushed (copied) the apps to the servers to configure the forwarders. The forwarders work just fine and are recognized by the Indexer. And the props as well as input apps work well. And I am able to search for the index data using:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="test_index"  sourcetype=test_sourcetype&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;All fields defined in props and transform file, show up correctly. These fields  also show correctly: host, source and sourcetype. I can see "sourcetype=test_sourcetype" in the events. But I am unable search events using:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;sourcetype=test_sourcetype&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Any help will be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Olavo&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185838#M37211</guid>
      <dc:creator>olavo123</dc:creator>
      <dc:date>2020-09-28T18:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185839#M37212</link>
      <description>&lt;P&gt;I forgot to add that : Both indexer and Forwarders are version 6.1.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Olavo&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2014 15:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185839#M37212</guid>
      <dc:creator>olavo123</dc:creator>
      <dc:date>2014-10-24T15:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185840#M37213</link>
      <description>&lt;P&gt;Also, I see that I cannot use the fields "host" to perform any searches.  I have to use the index= "  ", then only other options like "host" , etc become operational.&lt;/P&gt;

&lt;P&gt;-Olavo&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2014 15:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185840#M37213</guid>
      <dc:creator>olavo123</dc:creator>
      <dc:date>2014-10-24T15:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185841#M37214</link>
      <description>&lt;P&gt;It was my understanding that by default, the user roles only allow searches against index=main.  If you wanted to default into other indexes, you'd have to update your roles per app behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2014 17:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185841#M37214</guid>
      <dc:creator>jluste</dc:creator>
      <dc:date>2014-10-24T17:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185842#M37215</link>
      <description>&lt;P&gt;If you wish to have custom indexes searched by default you must update your Role(s) to include that index as part of the "Indexes searched by default."&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Settings&lt;/LI&gt;
&lt;LI&gt;Access controles&lt;/LI&gt;
&lt;LI&gt;Roles&lt;/LI&gt;
&lt;LI&gt;Select Role(s)&lt;/LI&gt;
&lt;LI&gt;Scroll down to "Indexes searched by default"&lt;/LI&gt;
&lt;LI&gt;Add test_index&lt;/LI&gt;
&lt;LI&gt;Click SAVE&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 24 Oct 2014 18:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185842#M37215</guid>
      <dc:creator>MartinMcNutt</dc:creator>
      <dc:date>2014-10-24T18:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185843#M37216</link>
      <description>&lt;P&gt;Note, this is unrelated to the app but rather controlled by the user's role.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2014 20:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185843#M37216</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-24T20:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to search using Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185844#M37217</link>
      <description>&lt;P&gt;Yes, that's it.  But I thought that this could also be set per application.  Do the user roles allow per app settings? (Not an admin)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 19:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-search-using-Sourcetype/m-p/185844#M37217</guid>
      <dc:creator>jluste</dc:creator>
      <dc:date>2014-10-27T19:07:42Z</dc:date>
    </item>
  </channel>
</rss>

