<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The Splunk search shows that events exist, but why does the Events tab show &amp;quot;No results found&amp;quot;? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208513#M60854</link>
    <description>&lt;P&gt;I am not able to understand the logic. There are something like 300,000+ events for this log file. So it scanned only 287 events and did not find any matches on these 287 events. &lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2016 11:32:19 GMT</pubDate>
    <dc:creator>yasinmoha</dc:creator>
    <dc:date>2016-04-22T11:32:19Z</dc:date>
    <item>
      <title>The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208504#M60845</link>
      <description>&lt;P&gt;I am trying to list specific events, but I am not able to view them. Splunk shows that events exist, but it comes up with no events found. Screenshot attached &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1249i26D72EAD620549C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 13:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208504#M60845</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-18T13:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208505#M60846</link>
      <description>&lt;P&gt;Could it be you have the No Event Sampling activated?&lt;BR /&gt;
Take a look at this: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Search/Retrieveasamplesetofevents#Specify_a_sampling_ratio"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Search/Retrieveasamplesetofevents#Specify_a_sampling_ratio&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Take a look at the following two values from your inspect job trace:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; resultCount     0
 scanCount     287
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now take a look at their &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Search/ViewsearchjobpropertieswiththeJobInspector"&gt;correspondent description&lt;/A&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;resultCount - The total number of results returned by the search. In other words, this is the subset of scanned events (represented by the scanCount) that actually matches the search terms.

scanCount - The number of events that are scanned or read off disk
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Specifically this bit:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;This is the subset of scanned events&lt;BR /&gt;
(represented by the scanCount) that&lt;BR /&gt;
actually matches the search terms.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;In summary, your search filter does not match any events you are reading off disk.&lt;BR /&gt;
Hope that makes sense. &lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 18:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208505#M60846</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-04-18T18:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208506#M60847</link>
      <description>&lt;P&gt;Event sampling returns me very few records. and not the actual set of records that match. This is a normal problem that I have even with another search that I was performing. &lt;/P&gt;

&lt;P&gt;There was another similair query I tried and when I filter based on date month it returns value for one particular month and not the other. &lt;/P&gt;

&lt;P&gt;I have splunk installed on my linux laptop. Could that have any implication in indexing. &lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 07:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208506#M60847</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-19T07:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208507#M60848</link>
      <description>&lt;P&gt;Running on a Linux laptop shouldn't make any difference.&lt;BR /&gt;
Could you try running your query in Smart Mode instead of Verbose?&lt;/P&gt;

&lt;P&gt;Do you get any results when running any other query?&lt;BR /&gt;
For instance, if you run the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal | head 10000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Do you get 10,000 results?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 09:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208507#M60848</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-04-19T09:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208508#M60849</link>
      <description>&lt;P&gt;I ran the index command and it returned me 10000 results. The case is sometime when I am adding more filter let me give another example. Where I tried to look up all log entries that had recall in them and it returned me 292 results. When I added recall AND fail*. It showed me 36 entries but no results displayed. When I did an inspect job I found that event count is 36 but available event count is 0. &lt;/P&gt;

&lt;P&gt;I guess there might be something wrong with the way I am writing the search query or may be indexing. &lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 09:40:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208508#M60849</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-19T09:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208509#M60850</link>
      <description>&lt;P&gt;Looks like I dont have enough Karma points to add more files. &lt;/P&gt;

&lt;P&gt;Scene 1 - This does not work&lt;/P&gt;

&lt;P&gt;1st query &lt;BR /&gt;
source=syslog.txt recall* --- Returns 292 records&lt;/P&gt;

&lt;P&gt;2nd query &lt;BR /&gt;
source=syslog.txt recall fail* -- Returns 36 records in event count but does not display results. &lt;/P&gt;

&lt;P&gt;But when I try &lt;/P&gt;

&lt;P&gt;source=syslog.txt migrat* fail* --- This query returns me results. &lt;/P&gt;

&lt;P&gt;And when I concatenate both the query it does not return any results. &lt;/P&gt;

&lt;P&gt;source=syslog.txt (migrat* fail*) AND (recall fail*)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208509#M60850</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2020-09-29T09:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208510#M60851</link>
      <description>&lt;P&gt;Can you run one of those searches that do not return any results but then click on Job &amp;gt; Inspect Job,  copy the report and paste it here as Code Sample (use the button with 1s and 0s above)?&lt;/P&gt;

&lt;P&gt;Maybe there's something in the Job Inspector telling us what's going on&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 13:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208510#M60851</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-04-19T13:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208511#M60852</link>
      <description>&lt;P&gt;Below is the job inspection report I hope its format your looking for. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Execution costs
Duration (seconds)      Component   Invocations     Input count     Output count
    0.00    command.fields  5   287     287
    0.23    command.search  5   -   287
    0.13    command.search.index    6   -   -
    0.00    command.search.filter   1   -   -
    0.00    command.search.calcfields   1   287     287
    0.00    command.search.fieldalias   1   287     287
    0.00    command.search.index.usec_1_8   5,325   -   -
    0.00    command.search.index.usec_512_4096  5   -   -
    0.00    command.search.index.usec_64_512    114     -   -
    0.00    command.search.index.usec_8_64  21  -   -
    0.06    command.search.kv   1   -   -
    0.03    command.search.rawdata  1   -   -
    0.01    command.search.typer    1   287     287
    0.00    command.search.lookups  1   287     287
    0.00    command.search.summary  5   -   -
    0.00    command.search.tags     1   287     287
    0.00    dispatch.check_disk_usage   1   -   -
    0.00    dispatch.createdSearchResultInfrastructure  1   -   -
    0.08    dispatch.evaluate   1   -   -
    0.08    dispatch.evaluate.search    1   -   -
    0.28    dispatch.fetch  6   -   -
    0.23    dispatch.localSearch    1   -   -
    0.00    dispatch.readEventsInResults    1   -   -
    0.23    dispatch.stream.local   5   -   -
    0.01    dispatch.timeline   6   -   -
    0.01    dispatch.writeStatus    6   -   -
    0.03    startup.configuration   1   -   -
    0.07    startup.handoff     1   -   -
Search job properties
canSummarize    0
createTime  2016-04-20T12:48:20.000+05:30
cursorTime  2015-09-28T16:00:00.000+05:30
custom  

{
    "search": "(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") opc* AND acf*"
}

defaultSaveTTL  604800
defaultTTL  600
delegate    None
diskUsage   122880
dispatchState   DONE
doneProgress    1.0
dropCount   0
eai:acl     

{
    "app": "search", 
    "can_write": "1", 
    "modifiable": "1", 
    "owner": "admin", 
    "perms": {
        "read": [
            "admin"
        ], 
        "write": [
            "admin"
        ]
    }, 
    "sharing": "global", 
    "ttl": "600"
}

earliestTime    2012-07-08T01:30:52.000+05:30
eventAvailableCount     0
eventCount  287
eventFieldCount     0
eventIsStreaming    True
eventIsTruncated    False
eventSearch     search (source="nafx.g1303v00'" OR source="nafx.g1304v00'") opc* AND acf*
eventSorting    desc
indexEarliestTime   1460630991
indexLatestTime     1460631052
isBatchModeSearch   False
isDone  True
isFailed    False
isFinalized     False
isPaused    False
isPreviewEnabled    True
isRealTimeSearch    False
isRemoteTimeline    False
isSaved     False
isSavedSearch   False
isTimeCursored  1
isZombie    False
keywords    acf* opc* source::nafx.g1303v00' source::nafx.g1304v00'
label   None
modifiedTime    2016-04-20T12:48:27.086+05:30
normalizedSearch    litsearch ( source="nafx.g1303v00'" OR source="nafx.g1304v00'" ) opc* AND acf* | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"
numPreviews     0
pid     21431
priority    5
remoteSearch    litsearch ( source="nafx.g1303v00'" OR source="nafx.g1304v00'" ) opc* AND acf* | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"
reportSearch    None
request     

{
    "adhoc_search_level": "verbose", 
    "auto_cancel": "30", 
    "check_risky_command": "false", 
    "custom.search": "(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") opc* AND acf*", 
    "earliest_time": null, 
    "indexedRealtime": null, 
    "latest_time": null, 
    "preview": "1", 
    "rf": "*", 
    "sample_ratio": "1", 
    "search": "search (source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") opc* AND acf*", 
    "status_buckets": "300", 
    "ui_dispatch_app": "search"
}

resultCount     0
resultIsStreaming   True
resultPreviewCount  0
runDuration     0.388
runtime     

{
    "auto_cancel": "30", 
    "auto_pause": "0"
}

sampleRatio     1
sampleSeed  0
scanCount   287
search  search (source="nafx.g1303v00'" OR source="nafx.g1304v00'") opc* AND acf*
searchCanBeEventType    1
searchProviders     

[
    "oc8001872801.ibm.com"
]

searchTotalBucketsCount     13
searchTotalEliminatedBucketsCount   0
sid     1461136700.12
statusBuckets   300
ttl     600
Additional info     timeline search.log 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Apr 2016 07:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208511#M60852</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-20T07:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208512#M60853</link>
      <description>&lt;P&gt;Ok, I think I might have the answer.&lt;BR /&gt;
Take a look at this two values from your inspect job trace:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; resultCount     0
 scanCount     287
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now take a look at their &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Search/ViewsearchjobpropertieswiththeJobInspector"&gt;correspondent description&lt;/A&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;resultCount - The total number of results returned by the search. In other words, this is the subset of scanned events (represented by the scanCount) that actually matches the search terms.

scanCount - The number of events that are scanned or read off disk
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Specifically this bit:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;This is the subset of scanned events&lt;BR /&gt;
(represented by the scanCount) that&lt;BR /&gt;
actually matches the search terms.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;In summary, your search filter does not match any events you are reading off disk.&lt;BR /&gt;
Hope that makes sense. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 15:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208512#M60853</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-04-20T15:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208513#M60854</link>
      <description>&lt;P&gt;I am not able to understand the logic. There are something like 300,000+ events for this log file. So it scanned only 287 events and did not find any matches on these 287 events. &lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 11:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208513#M60854</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-22T11:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208514#M60855</link>
      <description>&lt;P&gt;Yeah, that seems to be case.&lt;BR /&gt;
One way to verify this is to run all the following searches and compare the number of events you get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;--&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") 
| search opc*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;--&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") 
| search acf*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;--&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(source=\"nafx.g1303v00'\" OR source=\"nafx.g1304v00'\") 
| search opc* AND acf*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 22 Apr 2016 11:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208514#M60855</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-04-22T11:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208515#M60856</link>
      <description>&lt;P&gt;I deleted the source log file and added it again with a new index instead of the default index and now when I run this command I am able to see the records And I have created separate indexes for each of the log files. &lt;/P&gt;

&lt;P&gt;May be I used default index for all the log files which caused this issue. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 09:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208515#M60856</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-25T09:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208516#M60857</link>
      <description>&lt;P&gt;Are those sources quite large in size?  I've recently ran into this with a sourcetype that has very large log files.  My resolution was that I needed to specify the index I wanted to search.  I don't know exactly why this needed to occur but I have a hunch it's due to some sort of max being reached when scanning very large events without an index supplied.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 18:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208516#M60857</guid>
      <dc:creator>briancronrath</dc:creator>
      <dc:date>2018-08-03T18:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208517#M60858</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Did you succeed in solving your issue ?&lt;/P&gt;

&lt;P&gt;We've encounter the same problem:&lt;BR /&gt;
We are using a search &lt;CODE&gt;index=_internal Error&lt;/CODE&gt;&lt;BR /&gt;
We got the same result as the main screenshot .&lt;/P&gt;

&lt;P&gt;If we use the search  &lt;CODE&gt;index=_internal Error | table *&lt;/CODE&gt;We got a table in statistics with every fields. But still no event.&lt;/P&gt;

&lt;P&gt;We are using Splunk 6.6.x on a SHCluster/IdxCluster. &lt;BR /&gt;
After some tests, the error appears only on SH, not if we launch a search from the indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 15:40:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208517#M60858</guid>
      <dc:creator>vgtk4431</dc:creator>
      <dc:date>2018-09-14T15:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208518#M60859</link>
      <description>&lt;P&gt;We encounter the same error last Week (see my comment)&lt;/P&gt;

&lt;P&gt;The issue was on our limits.conf where we'd set a &lt;BR /&gt;
&lt;CODE&gt;[search]&lt;BR /&gt;
max_count=0&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;which prevents Splunk to store any events.&lt;BR /&gt;
&lt;STRONG&gt;Removing that settings resolved our issue&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 14:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208518#M60859</guid>
      <dc:creator>vgtk4431</dc:creator>
      <dc:date>2018-09-26T14:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: The Splunk search shows that events exist, but why does the Events tab show "No results found"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208519#M60860</link>
      <description>&lt;P&gt;Okay found a solution to a similar problem.&lt;BR /&gt;
ou limits.conf had the following conf :&lt;BR /&gt;
&lt;CODE&gt;[search]&lt;BR /&gt;
max_count=0&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This prevent splunk to store events as search results.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Removing the faulty settings resolve our search issue&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 14:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-Splunk-search-shows-that-events-exist-but-why-does-the/m-p/208519#M60860</guid>
      <dc:creator>vgtk4431</dc:creator>
      <dc:date>2018-09-26T14:40:11Z</dc:date>
    </item>
  </channel>
</rss>

