<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fix misleading &amp;quot;What to search&amp;quot;/Data Summary in Search &amp; Reporting? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488406#M4514</link>
    <description>&lt;P&gt;I am able to search logs in the past 5 minutes with no issue and Data Summary still shows 10 events from 2 months ago.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 20:45:52 GMT</pubDate>
    <dc:creator>ricotries</dc:creator>
    <dc:date>2020-04-28T20:45:52Z</dc:date>
    <item>
      <title>How to fix misleading "What to search"/Data Summary in Search &amp; Reporting?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488404#M4512</link>
      <description>&lt;P&gt;I have been working with new inputs for a testing environment and I noticed that one point the Data Summary said that there are 10 events indexed with the earliest and latest event being 2 months ago. At first I thought that the data indexed had been erased, but after checking some custom dashboards, executing searches, and checking the server's storage, all the data is still there. Why is the Data Summary not reflecting the reality of the amount of data indexed? It was working fine earlier in the day and the only changes I did were in inputs.conf and props.conf, I didn't change the configuration of the server or the indexes.&lt;/P&gt;
&lt;P&gt;Running 7.3.4 on a single-instance deployment.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 01:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488404#M4512</guid>
      <dc:creator>ricotries</dc:creator>
      <dc:date>2020-06-07T01:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix misleading "What to search"/Data Summary in Search &amp; Reporting?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488405#M4513</link>
      <description>&lt;P&gt;One possibility is that you may have temporarily had an indexer off line.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 20:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488405#M4513</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-04-28T20:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix misleading "What to search"/Data Summary in Search &amp; Reporting?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488406#M4514</link>
      <description>&lt;P&gt;I am able to search logs in the past 5 minutes with no issue and Data Summary still shows 10 events from 2 months ago.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 20:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488406#M4514</guid>
      <dc:creator>ricotries</dc:creator>
      <dc:date>2020-04-28T20:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix misleading "What to search"/Data Summary in Search &amp; Reporting?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488407#M4515</link>
      <description>&lt;P&gt;I don't know what triggered this issue to occur, but going into Settings &amp;gt; Users and Authentication &amp;gt; Access Controls &amp;gt; Roles and under any of the roles enabling "All non-internal indexes" as a Default fixes this.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 11:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-Data-Summary-in/m-p/488407#M4515</guid>
      <dc:creator>ricotries</dc:creator>
      <dc:date>2020-04-29T11:39:31Z</dc:date>
    </item>
  </channel>
</rss>

