<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk not showing logs when searched with index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624895#M217229</link>
    <description>&lt;P&gt;I can only say to review logs on both the sender side and splunkd.log. &amp;nbsp;My only experience with HEC is from Puppet's Splunk HEC app, and the only thing I had to figure out was how to force HEC to offer outdated SSL algorithm. (Not the app's fault, just to be clear.) &amp;nbsp;It is hard to read error messages that don't tell you how to solve. &amp;nbsp;But no error message would make it much harder - and absence of error remains a possibility. &amp;nbsp;That's why I suggested Admin forum.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2022 20:34:06 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2022-12-20T20:34:06Z</dc:date>
    <item>
      <title>Why is splunk not showing logs when searched with index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624779#M217193</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have integrated Splunk HEC with springboot .when i hit application and checked in splunk am unable to see logs in splunk search with given index .am using source type as log4j2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can any one help me .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 06:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624779#M217193</guid>
      <dc:creator>sindhuja</dc:creator>
      <dc:date>2022-12-20T06:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not showing logs when searched with index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624783#M217194</link>
      <description>&lt;P&gt;Looks like an ingestion problem, not a search problem. &amp;nbsp;You'll get better information by moving this to&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/bd-p/getting-data-in" target="_blank"&gt;Getting Data In&lt;/A&gt;. &amp;nbsp;Do you have any log indicating that HEC ingestion happened?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 03:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624783#M217194</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-20T03:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is splunk not showing logs when searched with index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624803#M217200</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252319"&gt;@sindhuja&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;said, it seems to be an ingestion problem, but to me more sure, you could use a larger search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=* sourcetype=log4j&lt;/LI-CODE&gt;&lt;P&gt;and see results.&lt;/P&gt;&lt;P&gt;Then you could analyze the input phase to identify where's the problem.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 08:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624803#M217200</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-20T08:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not showing logs when searched with index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624893#M217228</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i check HEC ingestion happened from my application side?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 19:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624893#M217228</guid>
      <dc:creator>sindhuja</dc:creator>
      <dc:date>2022-12-20T19:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not showing logs when searched with index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624895#M217229</link>
      <description>&lt;P&gt;I can only say to review logs on both the sender side and splunkd.log. &amp;nbsp;My only experience with HEC is from Puppet's Splunk HEC app, and the only thing I had to figure out was how to force HEC to offer outdated SSL algorithm. (Not the app's fault, just to be clear.) &amp;nbsp;It is hard to read error messages that don't tell you how to solve. &amp;nbsp;But no error message would make it much harder - and absence of error remains a possibility. &amp;nbsp;That's why I suggested Admin forum.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 20:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-splunk-not-showing-logs-when-searched-with-index/m-p/624895#M217229</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-20T20:34:06Z</dc:date>
    </item>
  </channel>
</rss>

