<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: i feel dumb, but I see no data when I search in splunk. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67779#M16941</link>
    <description>&lt;P&gt;this format gets me close, but i dont understand how to adapt all this to my input data.&lt;/P&gt;

&lt;P&gt;I dont understand alot of what you put in here or mean for me to replace, some is obvious, other parts are not.&lt;/P&gt;

&lt;P&gt;I'm using a Windows SPLUNK instance, and so do I need to escape all these caharacters?&lt;/P&gt;

&lt;P&gt;some stuff in here isnot anything i have ever seen.&lt;/P&gt;

&lt;P&gt;{chhose log/debug index}, etc...&lt;BR /&gt;
can you explain it more?  perhaps use a sample of my data from above for your example?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2012 14:45:12 GMT</pubDate>
    <dc:creator>lennyburns</dc:creator>
    <dc:date>2012-02-10T14:45:12Z</dc:date>
    <item>
      <title>i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67759#M16921</link>
      <description>&lt;P&gt;I created 8 data inputs, each one is supposed to tail log files mathing a certain whitelist regex.&lt;BR /&gt;
These inputs see the files (my preview worked and i see the # of files in the data inputs page.&lt;/P&gt;

&lt;P&gt;The Application im using for the inputs is SEARCH.&lt;/P&gt;

&lt;P&gt;When I go to the SEARCH app, I type a word I KNOW is in the logs, and I get nothing.&lt;BR /&gt;
I type * and I get nothing.&lt;/P&gt;

&lt;P&gt;I'm clearly missing something basic.&lt;/P&gt;

&lt;P&gt;This wasn't this hard when i did this a few years ago.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 00:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67759#M16921</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2012-02-08T00:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67760#M16922</link>
      <description>&lt;P&gt;Could you post the relevant stanza from inputs.conf?  Are you sending the data to an index you're then not searching for?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 00:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67760#M16922</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-02-08T00:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67761#M16923</link>
      <description>&lt;P&gt;Here is a sample of a few...&lt;/P&gt;

&lt;P&gt;[monitor://\XXX-vdi-csa01\c$\Documents and Settings\All Users\Application Data\VMware\VDM\logs]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
followTail = 1&lt;BR /&gt;
host = XXX-VDI-CSA01_DEBUG-LOG&lt;BR /&gt;
sourcetype = vmware_view_connection_broker_debug_log&lt;BR /&gt;
index = vmware_view_brokers&lt;BR /&gt;
blacklist = log-&lt;EM&gt;.txt&lt;BR /&gt;
whitelist = debug-&lt;/EM&gt;.txt&lt;/P&gt;

&lt;P&gt;[monitor://\XXX-vdi-csb01\c$\Documents and Settings\All Users\Application Data\VMware\VDM\logs]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
followTail = 1&lt;BR /&gt;
host = XXX-VDI-CSB01_LOG&lt;BR /&gt;
sourcetype = vmware_view_connection_server_log&lt;BR /&gt;
index = vmware_view_brokers&lt;BR /&gt;
blacklist = debug-&lt;EM&gt;.txt&lt;BR /&gt;
whitelist = log-&lt;/EM&gt;.txt&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67761#M16923</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2020-09-28T10:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67762#M16924</link>
      <description>&lt;P&gt;Here's the likely reason:&lt;BR /&gt;
index = vmware_view_brokers&lt;/P&gt;

&lt;P&gt;The summary app and by default your role will only search index=main by default.  Simply add:&lt;BR /&gt;
index=vmware_view_brokers&lt;/P&gt;

&lt;P&gt;to your search and you should see the data just fine&lt;/P&gt;

&lt;P&gt;You can change the default role that is searched under Manager&amp;gt; User Roles &amp;gt; your role.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67762#M16924</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T10:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67763#M16925</link>
      <description>&lt;P&gt;how can i make the default index the brokers index?  i plan to use splunk for nothign else but watching brokers.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 01:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67763#M16925</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2012-02-08T01:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67764#M16926</link>
      <description>&lt;P&gt;so, i did that...&lt;BR /&gt;
index="vmware_view_brokers"  WARN&lt;/P&gt;

&lt;P&gt;and i dont find any occurance of WARN&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67764#M16926</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2020-09-28T11:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67765#M16927</link>
      <description>&lt;P&gt;Usually, when I want to check that some data that I set to be indexed is present, I am as loose as possible with my search terms.&lt;/P&gt;

&lt;P&gt;Typically, I will search over all time for :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* OR index=_* &amp;lt;TERM&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...where &lt;CODE&gt;&lt;TERM&gt;&lt;/TERM&gt;&lt;/CODE&gt; is a string (unique, if possible) naturally delimited in the source by delimiters such as white spaces, colons, slashes, etc.&lt;/P&gt;

&lt;P&gt;Oh and there's no reason to feel dumb.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 01:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67765#M16927</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-02-08T01:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67766#M16928</link>
      <description>&lt;P&gt;What about with just the index specified, no other strings to filter.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 01:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67766#M16928</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-02-08T01:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67767#M16929</link>
      <description>&lt;P&gt;also make sure the indexes are actually created.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 03:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67767#M16929</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-02-08T03:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67768#M16930</link>
      <description>&lt;P&gt;You can search with just the index specified. The search will return all events in the index (constrained by your time range selection).&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 05:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67768#M16930</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-02-08T05:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67769#M16931</link>
      <description>&lt;P&gt;I get no results. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 14:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67769#M16931</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2012-02-08T14:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67770#M16932</link>
      <description>&lt;P&gt;I think this might be the problem..&lt;/P&gt;

&lt;P&gt;In the indexes section, the vmware_view_brokers index is only at 1MB and EVENT COUNT is 0, and the rest is N/A.&lt;/P&gt;

&lt;P&gt;argh.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67770#M16932</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2020-09-28T11:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67771#M16933</link>
      <description>&lt;P&gt;Hmm, this might take some more investigating.  What's the output of:&lt;BR /&gt;
./splunk bin splunk cmd btool indexes list --debug vmware_view_brokers&lt;/P&gt;

&lt;P&gt;Alternatively, if you have access to the IRC channel you could pop in there, then we could look deeper and then update this Question with the outcome.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67771#M16933</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67772#M16934</link>
      <description>&lt;P&gt;so i just run this command?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 18:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67772#M16934</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2012-02-08T18:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67773#M16935</link>
      <description>&lt;P&gt;C:\Program Files\Splunk\bin&amp;gt;btool indexes list --debug vmware_view_brokers&lt;BR /&gt;
search     [vmware_view_brokers]&lt;BR /&gt;
system     assureUTF8 = false&lt;BR /&gt;
system     blockSignSize = 0&lt;BR /&gt;
system     blockSignatureDatabase = _blocksignature&lt;BR /&gt;
search     coldPath = $SPLUNK_DB\vmware_view_brokers\colddb&lt;BR /&gt;
system     coldToFrozenDir =&lt;BR /&gt;
system     coldToFrozenScript =&lt;BR /&gt;
system     compressRawdata = true&lt;BR /&gt;
system     defaultDatabase = main&lt;BR /&gt;
system     enableOnlineBucketRepair = true&lt;BR /&gt;
system     enableRealtimeSearch = true&lt;BR /&gt;
system     frozenTimePeriodInSecs = 188697600&lt;BR /&gt;
search     homePath = $SPLUNK_DB\vmware_view_brokers\db&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67773#M16935</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2020-09-28T11:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67774#M16936</link>
      <description>&lt;P&gt;system     indexThreads = auto&lt;BR /&gt;
system     maxBloomBackfillBucketAge = 30d&lt;BR /&gt;
system     maxConcurrentOptimizes = 3&lt;BR /&gt;
system     maxDataSize = auto&lt;BR /&gt;
system     maxHotBuckets = 3&lt;BR /&gt;
system     maxHotIdleSecs = 0&lt;BR /&gt;
system     maxHotSpanSecs = 7776000&lt;BR /&gt;
system     maxMemMB = 5&lt;BR /&gt;
system     maxMetaEntries = 1000000&lt;BR /&gt;
system     maxRunningProcessGroups = 20&lt;BR /&gt;
system     maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;
system     maxTotalDataSizeMB = 500000&lt;BR /&gt;
system     maxWarmDBCount = 300&lt;BR /&gt;
system     memPoolMB = auto&lt;BR /&gt;
system     minRawFileSyncSecs = disable&lt;BR /&gt;
system     partialServiceMetaPeriod = 0&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 18:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67774#M16936</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2012-02-08T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67775#M16937</link>
      <description>&lt;P&gt;system     quarantineFutureSecs = 2592000&lt;BR /&gt;
system     quarantinePastSecs = 77760000&lt;BR /&gt;
system     rawChunkSizeBytes = 131072&lt;BR /&gt;
system     rotatePeriodInSecs = 60&lt;BR /&gt;
system     serviceMetaPeriod = 25&lt;BR /&gt;
system     suppressBannerList =&lt;BR /&gt;
system     sync = 0&lt;BR /&gt;
system     syncMeta = true&lt;BR /&gt;
search     thawedPath = $SPLUNK_DB\vmware_view_brokers\thaweddb&lt;BR /&gt;
system     throttleCheckPeriod = 15&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67775#M16937</guid>
      <dc:creator>lennyburns</dc:creator>
      <dc:date>2020-09-28T11:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67776#M16938</link>
      <description>&lt;P&gt;Ok, after trying to figure out why the wildcard "&lt;EM&gt;" wouldn't work in your inputs.conf, it was determined that it can't be used in the Splunk data preview or the stanza in inputs.conf. &lt;BR /&gt;
EX:[monitor:///Users/username/Desktop/tmp/`debug-&lt;/EM&gt;.txt`] Although the docs say differently. I tried and I got the same result.&lt;/P&gt;

&lt;P&gt;With that said, I had to create these configurations to get it to work:&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;BR /&gt;
[monitor:///Users/username/Desktop/tmp] &amp;lt;---location of debug.txt and log.txt logs&lt;BR /&gt;
whitelist = &lt;CODE&gt;(log-.*\.txt|debug-.*\.txt)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[source::.../tmp/debug...txt]&lt;BR /&gt;
sourcetype = debug&lt;BR /&gt;
TRANSFORMS-index = choose_debug_index&lt;/P&gt;

&lt;P&gt;[source::.../tmp/log...txt]&lt;BR /&gt;
sourcetype = log&lt;BR /&gt;
TRANSFORMS-index = choose_log_index&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[choose_debug_index]&lt;BR /&gt;
SOURCE_KEY = _raw&lt;BR /&gt;
REGEX = .*&lt;BR /&gt;
DEST_KEY = _MetaData:Index&lt;BR /&gt;
FORMAT = debugtest&lt;/P&gt;

&lt;P&gt;[choose_log_index]&lt;BR /&gt;
SOURCE_KEY = _raw&lt;BR /&gt;
REGEX = .*&lt;BR /&gt;
DEST_KEY = _MetaData:Index&lt;BR /&gt;
FORMAT = logtest &lt;/P&gt;

&lt;P&gt;NOTE: The names of the indexes and transforms stanzas above can be changed to what suits your needs.&lt;BR /&gt;
Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67776#M16938</guid>
      <dc:creator>sgarvin55</dc:creator>
      <dc:date>2020-09-28T11:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67777#M16939</link>
      <description>&lt;P&gt;there is a way to show code in an Answers posting. The "code" button in the input editor (looks like "101-010" will make anything you type in literal. There should also be a help link somewhere to the formatting codes so you can type them directly (it is in Markdown), but some fail has removed it.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2012 23:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67777#M16939</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-02-09T23:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: i feel dumb, but I see no data when I search in splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67778#M16940</link>
      <description>&lt;P&gt;I learn something new everyday!&lt;BR /&gt;
Thanks gkanapathy, I owe you a beer!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2012 00:55:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/i-feel-dumb-but-I-see-no-data-when-I-search-in-splunk/m-p/67778#M16940</guid>
      <dc:creator>sgarvin55</dc:creator>
      <dc:date>2012-02-10T00:55:02Z</dc:date>
    </item>
  </channel>
</rss>

