<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112582#M29579</link>
    <description>&lt;P&gt;You (probably) need to specify an index; try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* OR index=_* host="10.0.110.1"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 19 May 2015 14:48:23 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-05-19T14:48:23Z</dc:date>
    <item>
      <title>Can't search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112581#M29578</link>
      <description>&lt;P&gt;I am just getting started with Splunk at home on Ubuntu.  I'm gathering logs from my pfsense firewall and I can see that there are indexed events.  When trying to search for something, the search box gets disabled and a little "do not enter" or "no" sign shows up where the cursor is.  No results are returned.  &lt;/P&gt;

&lt;P&gt;I'm just typing in &lt;CODE&gt;host="10.0.110.1"&lt;/CODE&gt; in the search field.  &lt;/P&gt;

&lt;P&gt;I'm assuming that there isn't something running that needs to be.  I did switch the license from enterprise trial to the free 500meg/day license.&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2015 22:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112581#M29578</guid>
      <dc:creator>wiz561</dc:creator>
      <dc:date>2015-05-16T22:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112582#M29579</link>
      <description>&lt;P&gt;You (probably) need to specify an index; try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* OR index=_* host="10.0.110.1"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 May 2015 14:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112582#M29579</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-19T14:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112583#M29580</link>
      <description>&lt;P&gt;Thanks for the response.  I think the problem lies deeper than this.  I installed the *nix app and can sucessfully gather information from the local box.  Even though Splunk says it is receiving information, I don't think it's making it searchable for some reason.  &lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2015 15:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112583#M29580</guid>
      <dc:creator>wiz561</dc:creator>
      <dc:date>2015-05-19T15:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112584#M29581</link>
      <description>&lt;P&gt;See what Splunk is complaining about with this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*splunkd.log* log_level!=info | cluster showcount=t | table cluster_count _raw | sort -cluster_count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 May 2015 16:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112584#M29581</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-19T16:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112585#M29582</link>
      <description>&lt;P&gt;Did you add the &lt;CODE&gt;os&lt;/CODE&gt; index and any other custom index to the Search Index by default.  In the Web UI (Settings -&amp;gt; Access Controls -&amp;gt; Roles -&amp;gt; Admin -&amp;gt; scroll down to 'Indexes searched by default' and add the indexes you want to search by default.  I hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 16:32:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search/m-p/112585#M29582</guid>
      <dc:creator>amiracle</dc:creator>
      <dc:date>2015-06-30T16:32:24Z</dc:date>
    </item>
  </channel>
</rss>

