<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is everything &amp;quot;No results found&amp;quot; in Web Intelligence Beta? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66506#M180431</link>
    <description>&lt;P&gt;See my follow-up question below.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2011 20:27:32 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2011-08-29T20:27:32Z</dc:date>
    <item>
      <title>Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66502#M180427</link>
      <description>&lt;P&gt;Am trying to index web logs from an intranet site, so I did the setup for Web Intelligence as follows:&lt;BR /&gt;
    sourcetype="access_c*"&lt;/P&gt;

&lt;P&gt;Filters: I had a hard time making these blank.  Since this is an intranet site I don't want to filter out internal addresses or referring domains, so I sort of cheated, entered "192.168.1.1/32" as the IP filter, "*.example.com" as referring domain, etc. and excluded "/dev" from files.&lt;/P&gt;

&lt;P&gt;Next, I ran the backfill script and after a couple of days it was complete as well.  I did the sourcetype search and edited the CSV file.&lt;/P&gt;

&lt;P&gt;I can see that the data was indexed, that the access_c* filter worked, but no matter where I go in the Web Intelligence app, I get "No results found."&lt;/P&gt;

&lt;P&gt;What can I check here?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2011 17:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66502#M180427</guid>
      <dc:creator>mikeely</dc:creator>
      <dc:date>2011-08-29T17:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66503#M180428</link>
      <description>&lt;P&gt;You make a good point regarding the need for an option to "leave blank" one or more of the setup items.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2011 18:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66503#M180428</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-08-29T18:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66504#M180429</link>
      <description>&lt;P&gt;If you hover your mouse next to "No results found", Splunk should present a "More Info..." link.  What is the search that you see in the resultant search profiler popup?&lt;/P&gt;

&lt;P&gt;Similarly, what happens on the setup page when you click on the "Preview" links?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2011 18:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66504#M180429</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-08-29T18:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66505#M180430</link>
      <description>&lt;P&gt;Thanks.  I sort of cheated as we're 10.*/8 and such, but leaving them blank would be preferred.  Really though, I'd just as soon have valid data coming from this app and right now I don't.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2011 19:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66505#M180430</guid>
      <dc:creator>mikeely</dc:creator>
      <dc:date>2011-08-29T19:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66506#M180431</link>
      <description>&lt;P&gt;See my follow-up question below.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2011 20:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66506#M180431</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-08-29T20:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66507#M180432</link>
      <description>&lt;P&gt;If I go to the dashboard and select "Today" as a time reference, URI visits for example shows this: &lt;/P&gt;

&lt;P&gt;search host=* [ stats count | addinfo | eval range=info_max_time - info_min_time | eval search=if(range&amp;lt;=3605, "index=wi_summary_fivemin", if(range&amp;lt;=(86400+3600),"index=wi_summary_hourly","index=wi_summary_daily")) ] source="Pageview*" sourcename="*"  | top  uri&lt;/P&gt;

&lt;P&gt;Previewing for "access_c*" returns results, none of the other filters do but then again I specifically selected them so I wouldn't filter out any intranet traffic. I can tune them so they match all but that's not what I want to do.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66507#M180432</guid>
      <dc:creator>mikeely</dc:creator>
      <dc:date>2020-09-28T09:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66508#M180433</link>
      <description>&lt;P&gt;index=wi_summary_hourly &lt;BR /&gt;
these are indexes thus you should use the correct indexes. &lt;BR /&gt;
i have changed the above indexes i do get some results. however i have not been able to similarly put the date in different indexes based on time range which seems to be the case here. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66508#M180433</guid>
      <dc:creator>Akili</dc:creator>
      <dc:date>2020-09-28T10:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66509#M180434</link>
      <description>&lt;P&gt;Check your Apache logging format.   The jobs running behind the tables require the "combined" format.   You may be in "common" format.  &lt;/P&gt;

&lt;P&gt;The jobs are using search filters based on referrer or client UI.  This causes an empty result set if your logs are in "common" format.  &lt;/P&gt;

&lt;P&gt;A simple way to test this is to try comparing the following searches in the web intelligence search window:  "eventtype=pageview eventtype=ua-browser-*"  vs. "eventtype=pageview".   If you have no results on the first one but plenty of results for the second one, then the jobs I'm talking about are likely failing with no results. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2012 19:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66509#M180434</guid>
      <dc:creator>pde7</dc:creator>
      <dc:date>2012-06-12T19:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is everything "No results found" in Web Intelligence Beta?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66510#M180435</link>
      <description>&lt;P&gt;change the time range to All time&lt;/P&gt;

&lt;P&gt;in beta by default the results shown are past 24 hours.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2013 17:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-everything-quot-No-results-found-quot-in-Web-Intelligence/m-p/66510#M180435</guid>
      <dc:creator>eashwar</dc:creator>
      <dc:date>2013-01-05T17:52:22Z</dc:date>
    </item>
  </channel>
</rss>

