<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Show source not available in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147044#M185287</link>
    <description>&lt;P&gt;Solution: Making sure the search is well finalized before getting to source of an result/event.&lt;/P&gt;

&lt;P&gt;Have tested as user and admin, encountered this error if the search is still running or not finalized. vis-a-vis when search is finalized have not encountered this issue, may take a bit of time to load the source.&lt;/P&gt;</description>
    <pubDate>Mon, 05 May 2014 18:58:11 GMT</pubDate>
    <dc:creator>rthakalapally1</dc:creator>
    <dc:date>2014-05-05T18:58:11Z</dc:date>
    <item>
      <title>Show source not available</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147042#M185285</link>
      <description>&lt;P&gt;Hi.  For some events in a particular index, users (including Admins) are getting an error of "Show Source not available for this event" when we try to display it.&lt;/P&gt;

&lt;P&gt;The article &lt;A href="http://answers.splunk.com/answers/32087/show-source-not-available-for-this-event"&gt;here&lt;/A&gt; suggests that this was reported and found to be a bug, but that it would be fixed as of 5.0.3&lt;/P&gt;

&lt;P&gt;We are on 5.0.3 and are experiencing the problem.&lt;/P&gt;

&lt;P&gt;Anyone else ever see this?  This is with a VERY basic search consisting of 'index=INDEXNAME' and a bare-word search term.  Nothing more.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2013 20:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147042#M185285</guid>
      <dc:creator>Sqig</dc:creator>
      <dc:date>2013-11-18T20:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Show source not available</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147043#M185286</link>
      <description>&lt;P&gt;You should open a support ticket, if you haven't already. This is probably beyond any community member's ability to fix...&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2013 03:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147043#M185286</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-11-19T03:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Show source not available</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147044#M185287</link>
      <description>&lt;P&gt;Solution: Making sure the search is well finalized before getting to source of an result/event.&lt;/P&gt;

&lt;P&gt;Have tested as user and admin, encountered this error if the search is still running or not finalized. vis-a-vis when search is finalized have not encountered this issue, may take a bit of time to load the source.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 18:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147044#M185287</guid>
      <dc:creator>rthakalapally1</dc:creator>
      <dc:date>2014-05-05T18:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Show source not available</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147045#M185288</link>
      <description>&lt;P&gt;You could also try running a historical search, if you are running a realtime search.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 15:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-source-not-available/m-p/147045#M185288</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2014-06-03T15:13:52Z</dc:date>
    </item>
  </channel>
</rss>

