<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk searches does not return expected values even though the data is completed in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709313#M239720</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently migrated from a standalone Search Head to a clustered one. However, we are having some issue running some search commands. For example, this is a query that is not working on the new SH cluster&lt;/P&gt;&lt;P&gt;sourcetype=dataA index=deptA | where critC &amp;gt; 25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the old search head, this query runs fine and we see the results as expected. But on the SH cluster, this doesn't yield anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have run the "sourcetype=dataA index=deptA" search query by itself, and they both see the same events. I am not sure why the search with (| where citC &amp;gt; 25) on the standalone SH would work and the cluster would not. Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 14:03:19 GMT</pubDate>
    <dc:creator>josephp</dc:creator>
    <dc:date>2025-01-21T14:03:19Z</dc:date>
    <item>
      <title>Splunk searches does not return expected values even though the data is completed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709313#M239720</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently migrated from a standalone Search Head to a clustered one. However, we are having some issue running some search commands. For example, this is a query that is not working on the new SH cluster&lt;/P&gt;&lt;P&gt;sourcetype=dataA index=deptA | where critC &amp;gt; 25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the old search head, this query runs fine and we see the results as expected. But on the SH cluster, this doesn't yield anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have run the "sourcetype=dataA index=deptA" search query by itself, and they both see the same events. I am not sure why the search with (| where citC &amp;gt; 25) on the standalone SH would work and the cluster would not. Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709313#M239720</guid>
      <dc:creator>josephp</dc:creator>
      <dc:date>2025-01-21T14:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk searches does not return expected values even though the data is completed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709314#M239721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275149"&gt;@josephp&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you defined on the Search Head the field extraction for&amp;nbsp;&lt;SPAN&gt;critC&amp;nbsp;field?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if yes, the grants for this field are App or Global?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if App, are you in the same App?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:06:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709314#M239721</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-21T14:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk searches does not return expected values even though the data is completed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709315#M239722</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;May I have a pointer to splunk document for this "&lt;SPAN&gt;if yes, the grants for this field are App or Global?"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709315#M239722</guid>
      <dc:creator>josephp</dc:creator>
      <dc:date>2025-01-21T14:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk searches does not return expected values even though the data is completed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709333#M239727</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275149"&gt;@josephp&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the point is that if you share the field extraction at App level, outside this app you cannot see the field.&lt;/P&gt;&lt;P&gt;So repeat your search in the App where you extracted the field and see if you have results.&lt;/P&gt;&lt;P&gt;If you need to run the search outside the app where the extraction is defined, share the field extraction at Global level.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 15:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-searches-does-not-return-expected-values-even-though-the/m-p/709333#M239727</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-21T15:40:41Z</dc:date>
    </item>
  </channel>
</rss>

