<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events not found, even though dashboard says there are in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91719#M23661</link>
    <description>&lt;P&gt;I was able to change the timestamp being produced by the program and Splunk now identifies it correctly.  It's very odd however that it would just stop reading the correct timestamp from one minute to the next when nothing changed in the program, the logs themselves nor splunk&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jul 2012 17:12:43 GMT</pubDate>
    <dc:creator>gregwilliams</dc:creator>
    <dc:date>2012-07-05T17:12:43Z</dc:date>
    <item>
      <title>Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91714#M23656</link>
      <description>&lt;P&gt;I have a universal forwarder pulling in a log file from a linux server.  It has been working just fine up until the other day.  The Summary dashboard shows events are coming in, however when I search for anything related to the source, sourcetype, anything within the event, I get "No Matching Events found".  I can see events from other servers no problem.  Nothing in the infrastructure nor Splunk config has changed.  I am an admin, so I should be seeing everything.  Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 15:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91714#M23656</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-07-05T15:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91715#M23657</link>
      <description>&lt;P&gt;Perhaps it's writing to another index than the one(s) you're searching?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 15:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91715#M23657</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-07-05T15:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91716#M23658</link>
      <description>&lt;P&gt;That actually helped me figure it out.  Apparently Splunk is reading the timestamp on the logs differently now and putting them in completely different days.  So for example 07/05-08:25:43 is being read as May 8 8:25:43.  It's ignoring month.  I'll try to figure out how to change that.  Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91716#M23658</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-07-05T16:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91717#M23659</link>
      <description>&lt;P&gt;Check TIMESTAMP_FORMAT in props.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91717#M23659</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-07-05T16:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91718#M23660</link>
      <description>&lt;P&gt;I added this in my props.conf but without luck.&lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
TIME_FORMAT=%m/%d-%h:%m:%s &lt;/P&gt;

&lt;P&gt;The event comes in as:&lt;/P&gt;

&lt;P&gt;07/05-10:01:01&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:39:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91718#M23660</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-07-05T16:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91719#M23661</link>
      <description>&lt;P&gt;I was able to change the timestamp being produced by the program and Splunk now identifies it correctly.  It's very odd however that it would just stop reading the correct timestamp from one minute to the next when nothing changed in the program, the logs themselves nor splunk&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 17:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91719#M23661</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-07-05T17:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Events not found, even though dashboard says there are</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91720#M23662</link>
      <description>&lt;P&gt;Problem solved.  The problem was Splunk was reading the log timestamp incorrectly.  What's odd however is that the log timestamp format never changed, but Splunk was just now unable to read it correctly.  I was able to configure the program sending the log to include the year instead of just the date.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 17:15:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Events-not-found-even-though-dashboard-says-there-are/m-p/91720#M23662</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-07-05T17:15:10Z</dc:date>
    </item>
  </channel>
</rss>

