<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Contradiction of search result ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80140#M20269</link>
    <description>&lt;P&gt;I found the search contradiction between "index=* host=splkc" and "host=splkc".&lt;BR /&gt;
Though the former search find some results, the later is not.&lt;BR /&gt;
Why ?&lt;BR /&gt;
&lt;IMG src="http://splunk-base.splunk.com//storage/test00.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/test_3.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Following environment.&lt;BR /&gt;
Splunk version : 5.02&lt;BR /&gt;
Operating System : Windows Server 2008 R2 64bit&lt;BR /&gt;
Data : WMI Polling Data&lt;/P&gt;</description>
    <pubDate>Sun, 31 Mar 2013 04:29:21 GMT</pubDate>
    <dc:creator>sunrise</dc:creator>
    <dc:date>2013-03-31T04:29:21Z</dc:date>
    <item>
      <title>Contradiction of search result ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80140#M20269</link>
      <description>&lt;P&gt;I found the search contradiction between "index=* host=splkc" and "host=splkc".&lt;BR /&gt;
Though the former search find some results, the later is not.&lt;BR /&gt;
Why ?&lt;BR /&gt;
&lt;IMG src="http://splunk-base.splunk.com//storage/test00.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/test_3.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Following environment.&lt;BR /&gt;
Splunk version : 5.02&lt;BR /&gt;
Operating System : Windows Server 2008 R2 64bit&lt;BR /&gt;
Data : WMI Polling Data&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2013 04:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80140#M20269</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-03-31T04:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Contradiction of search result ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80141#M20270</link>
      <description>&lt;P&gt;If there is no index term in your search,  then Splunk will search the indexes that are listed as the default indexes for your role.   You can see this list by going to Manager &amp;gt; Authentication &amp;gt; Roles.   &lt;/P&gt;

&lt;P&gt;Since by default users just have &lt;CODE&gt;index="main"&lt;/CODE&gt; in that list,  then what's happening in the first screenshot is it's only searching &lt;CODE&gt;index="main"&lt;/CODE&gt;, and there are no events from that host there. &lt;/P&gt;

&lt;P&gt;In the second screenshot you've searched for &lt;CODE&gt;index="*"&lt;/CODE&gt;.  this tells splunkd that you'd like to search all of the indexes that you have permission to search, and in an index called "wmi_performancelog", there are some events from that host. &lt;/P&gt;

&lt;P&gt;It's a little confusing that the absence of an index term is actually a more restrictive search than index=*, but that's what's happening here. &lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2013 05:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80141#M20270</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-03-31T05:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Contradiction of search result ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80142#M20271</link>
      <description>&lt;P&gt;Thank you sideview for quick response and explanation.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2013 10:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Contradiction-of-search-result/m-p/80142#M20271</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-03-31T10:27:20Z</dc:date>
    </item>
  </channel>
</rss>

