<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Performance check in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619284#M215236</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240781"&gt;@NizanCohen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, you need an app or an add-on to parse your logs, so you have two solutions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;install one add-on from Splunkbase (e.g. the one I hinted),&lt;/LI&gt;&lt;LI&gt;create your own parsing rules.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;if your problem is only timestamp, you could add TIME_FORMAT to your sourcetyoe and quickly solve your need, otherwise, it's easier to install a TA from Splunkbase.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 13:22:39 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-11-02T13:22:39Z</dc:date>
    <item>
      <title>Performance check- How can I check why I'm not getting any results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619241#M215222</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;
&lt;P&gt;I use Splunk on my workplace and recently I feel like it's performance is decreasing. Basic search queries like my username or email address would provide results, now it wouldn't.&lt;/P&gt;
&lt;P&gt;Doesn't matter the time frame I choose, zero events.&lt;/P&gt;
&lt;P&gt;I was told that an app called "estreamer" was down and one of the infrastructure worker fixed it and claimed to restore all missing data. It was last Thursday. Sadly, he's not familiar with this system so I need to address the issue when I talk with him.&lt;/P&gt;
&lt;P&gt;Today, I still cannot search these basic strings, it gives zero events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea how I check what's wrong so I can tell the infra worker to fix certain issue/index/app?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 12:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619241#M215222</guid>
      <dc:creator>NizanCohen</dc:creator>
      <dc:date>2022-11-02T12:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Performance check</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619244#M215225</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240781"&gt;@NizanCohen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you using the estreamer TA (&lt;A href="https://splunkbase.splunk.com/app/3662)?" target="_blank"&gt;https://splunkbase.splunk.com/app/3662)&lt;/A&gt;&amp;nbsp;from splunkbase?&lt;/P&gt;&lt;P&gt;So, pleasae, check if you have today's events in the 11th of february.&lt;/P&gt;&lt;P&gt;If you have today's events with timestamp of 11th of february means that you have a wrong timestamp recognition that you can solve using an add-on from splunkbase or setting the TIME_FORMAT on your indexers or (if present) Heavy Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 08:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619244#M215225</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-02T08:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Performance check</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619274#M215230</link>
      <description>&lt;P&gt;Not sure about the app, I don't find it on the upper left "app" menu.&lt;/P&gt;&lt;P&gt;But, if I search for index=estreamer I get events..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other question, how can I search an index that was recently stopped being used? maybe that will give me the needed information.. even though, searching the basic string with "all time" would not return anything..&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 12:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619274#M215230</guid>
      <dc:creator>NizanCohen</dc:creator>
      <dc:date>2022-11-02T12:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Performance check</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619278#M215232</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240781"&gt;@NizanCohen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you cannot find this app in the app list because it isn't visible, so you have to search it in [Apps &amp;gt; manage Apps].&lt;/P&gt;&lt;P&gt;About the estreamer problem, is it solved or not?&lt;/P&gt;&lt;P&gt;if yes, please accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;About the other question, don't add a new question to another one, because in this way, less people will help you, it's always better to open a new Question.&lt;/P&gt;&lt;P&gt;Anyway, if you search index=&amp;lt;your_index&amp;gt; and you don't have any event with "All Time", this means that you haven't any event on that index, so you cannot search anything.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 13:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619278#M215232</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-02T13:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Performance check</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619279#M215233</link>
      <description>&lt;P&gt;No, I cannot find the estreamer app in "manage apps".&lt;/P&gt;&lt;P&gt;Any other idea why I experience this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 13:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619279#M215233</guid>
      <dc:creator>NizanCohen</dc:creator>
      <dc:date>2022-11-02T13:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Performance check</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619284#M215236</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240781"&gt;@NizanCohen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, you need an app or an add-on to parse your logs, so you have two solutions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;install one add-on from Splunkbase (e.g. the one I hinted),&lt;/LI&gt;&lt;LI&gt;create your own parsing rules.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;if your problem is only timestamp, you could add TIME_FORMAT to your sourcetyoe and quickly solve your need, otherwise, it's easier to install a TA from Splunkbase.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 13:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Performance-check-How-can-I-check-why-I-m-not-getting-any/m-p/619284#M215236</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-02T13:22:39Z</dc:date>
    </item>
  </channel>
</rss>

