<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are there no results found in a search while exploring the search tutorial? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400726#M168731</link>
    <description>&lt;P&gt;@rogue_carrot also it would be better to unzip the log files to a folder and Monitor entire Folder using Splunk.&lt;/P&gt;

&lt;P&gt;Once you have added the complete folder Splunk will give you an option to &lt;CODE&gt;Start Searching&lt;/CODE&gt;, which will build the required query based on settings during Add Data Wizard.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/GetthetutorialdataintoSplunk#Use_the_Add_Data_wizard"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/GetthetutorialdataintoSplunk#Use_the_Add_Data_wizard&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jun 2018 06:29:52 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2018-06-24T06:29:52Z</dc:date>
    <item>
      <title>Why are there no results found in a search while exploring the search tutorial?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400724#M168729</link>
      <description>&lt;P&gt;Hello Team Splunk,&lt;/P&gt;

&lt;P&gt;I am following the simple search tutorial featuring logs in zip files from the fictitious company, "Buttercup Games". The problem is after 1) uploading the zip files, 2) viewing the sources in the data summary, and then 3) clicking on the source I do not 4) see any data in the search. This seems like I am missing something very important. So I wanted to check in with you all to see if you could help me figure out what is going wrong. Figure 1 below shows that there are no results in a search when there should be. Figure 2 shows that there are over thirty-thousand things in the log file that should probably appear in the search. What am I missing? &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="No results in a search for the vendor_sales.log in the tutorialdata.zip file. Error detected."&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5254i0D541E27CAAA22A6/image-size/large?v=v2&amp;amp;px=999" role="button" title="No results in a search for the vendor_sales.log in the tutorialdata.zip file. Error detected." alt="No results in a search for the vendor_sales.log in the tutorialdata.zip file. Error detected." /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;EM&gt;Figure 1&lt;/EM&gt;: No results&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30 thousand plus count for vendor_sales.log file in sources view of data summary. "&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5255i91445677170BA2CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="30 thousand plus count for vendor_sales.log file in sources view of data summary. " alt="30 thousand plus count for vendor_sales.log file in sources view of data summary. " /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;EM&gt;Figure 2&lt;/EM&gt;: 30K plus count for vendor_sales.log file - why doesn't anything show up in a search&lt;/P&gt;

&lt;P&gt;The tutorial I am following is at the following URL: &lt;A href="http://docs.splunk%5Bdot%5Dcom/Documentation/Splunk/7.1.1/SearchTutorial/Aboutthesearchapp#"&gt;http://docs.splunk[dot]com/Documentation/Splunk/7.1.1/SearchTutorial/Aboutthesearchapp#&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thank-you for reading this. &lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 20:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400724#M168729</guid>
      <dc:creator>rogue_carrot</dc:creator>
      <dc:date>2018-06-23T20:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there no results found in a search while exploring the search tutorial?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400725#M168730</link>
      <description>&lt;P&gt;you need to add &lt;CODE&gt;index = &amp;lt;your_index&amp;gt;&lt;/CODE&gt; or &lt;CODE&gt;index=*&lt;/CODE&gt; before your search&lt;BR /&gt;
the administrator, that has admin role, does not have indexes search by default defined in its role&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 21:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400725#M168730</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-06-23T21:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there no results found in a search while exploring the search tutorial?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400726#M168731</link>
      <description>&lt;P&gt;@rogue_carrot also it would be better to unzip the log files to a folder and Monitor entire Folder using Splunk.&lt;/P&gt;

&lt;P&gt;Once you have added the complete folder Splunk will give you an option to &lt;CODE&gt;Start Searching&lt;/CODE&gt;, which will build the required query based on settings during Add Data Wizard.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/GetthetutorialdataintoSplunk#Use_the_Add_Data_wizard"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/GetthetutorialdataintoSplunk#Use_the_Add_Data_wizard&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 06:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400726#M168731</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-06-24T06:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there no results found in a search while exploring the search tutorial?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400727#M168732</link>
      <description>&lt;P&gt;I tried specifying an index with the wildcard, index=*, but this did not change anything. Still there are no results in the search. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; Please see the following screenshot. &lt;BR /&gt;
&lt;IMG src="https://i.imgur.com/UgDAZMe.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 01:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400727#M168732</guid>
      <dc:creator>rogue_carrot</dc:creator>
      <dc:date>2018-06-25T01:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there no results found in a search while exploring the search tutorial?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400728#M168733</link>
      <description>&lt;P&gt;I figured out my problem. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Feels great... &lt;/P&gt;

&lt;P&gt;In the time selector the search was looking for the &lt;STRONG&gt;Last 24 hours&lt;/STRONG&gt;. I changed this to search &lt;STRONG&gt;All time&lt;/STRONG&gt; and behold my data was there! Or my events were there, or whatever that stuff is that should be there but was not earlier that necessitated this question. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;Please see the screenshot that follows. Pay attention to the "All time" in the drop down to the left of the magnifine glass symbol. I think someone should update the tutorial for the Splunk noob trying to find their way through the stress of trying to scale a learning curve.&lt;BR /&gt;
&lt;IMG src="https://i.imgur.com/C1VD9BD.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 01:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-no-results-found-in-a-search-while-exploring-the/m-p/400728#M168733</guid>
      <dc:creator>rogue_carrot</dc:creator>
      <dc:date>2018-06-25T01:55:48Z</dc:date>
    </item>
  </channel>
</rss>

