<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search without index not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85412#M21813</link>
    <description>&lt;P&gt;I installed latest Splunk and added splunkforwarder to index log data. Everything looks fine except that search doesn't return any data without specifying the index name, i.e&lt;/P&gt;

&lt;P&gt;sourcetype="jetty" &lt;/P&gt;

&lt;P&gt;doesn't work&lt;/P&gt;

&lt;P&gt;but &lt;/P&gt;

&lt;P&gt;index="app" sourcetype="jetty"&lt;/P&gt;

&lt;P&gt;works&lt;/P&gt;

&lt;P&gt;Any reason why search doesn't work without the index in the search query?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2013 18:32:06 GMT</pubDate>
    <dc:creator>aupadhya</dc:creator>
    <dc:date>2013-01-11T18:32:06Z</dc:date>
    <item>
      <title>Search without index not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85412#M21813</link>
      <description>&lt;P&gt;I installed latest Splunk and added splunkforwarder to index log data. Everything looks fine except that search doesn't return any data without specifying the index name, i.e&lt;/P&gt;

&lt;P&gt;sourcetype="jetty" &lt;/P&gt;

&lt;P&gt;doesn't work&lt;/P&gt;

&lt;P&gt;but &lt;/P&gt;

&lt;P&gt;index="app" sourcetype="jetty"&lt;/P&gt;

&lt;P&gt;works&lt;/P&gt;

&lt;P&gt;Any reason why search doesn't work without the index in the search query?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85412#M21813</guid>
      <dc:creator>aupadhya</dc:creator>
      <dc:date>2013-01-11T18:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Search without index not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85413#M21814</link>
      <description>&lt;P&gt;By default only the main index is searched. You can change which indexes are searched by default for a user and/or role in the manager in the web interface, Manager -&amp;gt; Access Controls.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85413#M21814</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-11T18:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Search without index not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85414#M21815</link>
      <description>&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 19:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85414#M21815</guid>
      <dc:creator>aupadhya</dc:creator>
      <dc:date>2013-01-11T19:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Search without index not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85415#M21816</link>
      <description>&lt;P&gt;Assuming the data exists, this behavior is dependent on the default settings for the role.  If you want the "app" index to be searchable by default, just add that index to "Indexes searched by default" for the role in question.  &lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Screen_Shot_2013-01-11_at_2.26.23_PM.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 22:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85415#M21816</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-01-11T22:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Search without index not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85416#M21817</link>
      <description>&lt;P&gt;set default in access control as: index!=_*&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 16:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-without-index-not-working/m-p/85416#M21817</guid>
      <dc:creator>rishrai</dc:creator>
      <dc:date>2017-01-25T16:29:07Z</dc:date>
    </item>
  </channel>
</rss>

