<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting 0 results when trying to filter my search by including a specific sourcetype? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230300#M68266</link>
    <description>&lt;P&gt;Check with your Splunk admin. It is possible to restrict access to specific sourcetypes&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Security/Addandeditroleswithauthorizeconf#Search_filter_format"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/Security/Addandeditroleswithauthorizeconf#Search_filter_format&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 23:45:20 GMT</pubDate>
    <dc:creator>sundareshr</dc:creator>
    <dc:date>2016-08-16T23:45:20Z</dc:date>
    <item>
      <title>Why am I getting 0 results when trying to filter my search by including a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230296#M68262</link>
      <description>&lt;P&gt;I'm facing an issue which I'm simply unable to understand&lt;/P&gt;

&lt;P&gt;I ran a search, simply by specifying the index I want to search in like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After this, I selected one of the values which were displayed in the top 10 for the sourcetype field, and added it to my search, so I had:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index sourcetype=my:sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And then, I got 0 results. I haven't changed the time picker or anything else, and I'm unable to understand why I'm not getting any results. Checking with the metadata command, I have thousands of events with this sourcetype in the index, and Splunk is displaying this sourcetype in the values of the field, but for some reason I can't run a search for it.&lt;/P&gt;

&lt;P&gt;Edit:&lt;/P&gt;

&lt;P&gt;When I'm not narrowing my search with that filer, I see the events with that particular sourcetype&lt;/P&gt;

&lt;P&gt;Edit2:&lt;/P&gt;

&lt;P&gt;Searching with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index sourcetype=*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;is not yielding any events with this problematic sourcetype.&lt;BR /&gt;
The sourcetype itself if set by props.conf, could this cause any issues? &lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 15:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230296#M68262</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2016-08-16T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting 0 results when trying to filter my search by including a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230297#M68263</link>
      <description>&lt;P&gt;Maybe, add double quotes around source type.&lt;/P&gt;

&lt;P&gt;index=my_index sourcetype="my:sourcetype"&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 15:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230297#M68263</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-08-16T15:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting 0 results when trying to filter my search by including a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230298#M68264</link>
      <description>&lt;P&gt;Yes, when I clicked the value from the list, it automatically added, it didn't work either&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 15:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230298#M68264</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2016-08-16T15:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting 0 results when trying to filter my search by including a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230299#M68265</link>
      <description>&lt;P&gt;Simply when you search for &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=my:sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;what it returns&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 15:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230299#M68265</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-08-16T15:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting 0 results when trying to filter my search by including a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230300#M68266</link>
      <description>&lt;P&gt;Check with your Splunk admin. It is possible to restrict access to specific sourcetypes&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Security/Addandeditroleswithauthorizeconf#Search_filter_format"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/Security/Addandeditroleswithauthorizeconf#Search_filter_format&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 23:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-0-results-when-trying-to-filter-my-search-by/m-p/230300#M68266</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-08-16T23:45:20Z</dc:date>
    </item>
  </channel>
</rss>

