<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does search typeahead no longer show &amp;quot;matching terms&amp;quot; after I upgraded to Splunk 6.3? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277836#M83816</link>
    <description>&lt;P&gt;I upgraded to Splunk 6.3 and it's working beautifully, however, I no longer get "matching terms" as I type in the search box.&lt;/P&gt;

&lt;P&gt;In previous versions of Splunk, if I typed: &lt;CODE&gt;err&lt;/CODE&gt; in the search box, I would see error=300, errors=402, errored=23 as typehead matching terms. Now I only see the term error show up in "matching search". There seems to be no matching term as you search now? I have auto-open turned on the search assistant.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Oct 2015 21:25:54 GMT</pubDate>
    <dc:creator>rroberts</dc:creator>
    <dc:date>2015-10-20T21:25:54Z</dc:date>
    <item>
      <title>Why does search typeahead no longer show "matching terms" after I upgraded to Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277836#M83816</link>
      <description>&lt;P&gt;I upgraded to Splunk 6.3 and it's working beautifully, however, I no longer get "matching terms" as I type in the search box.&lt;/P&gt;

&lt;P&gt;In previous versions of Splunk, if I typed: &lt;CODE&gt;err&lt;/CODE&gt; in the search box, I would see error=300, errors=402, errored=23 as typehead matching terms. Now I only see the term error show up in "matching search". There seems to be no matching term as you search now? I have auto-open turned on the search assistant.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 21:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277836#M83816</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2015-10-20T21:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search typeahead no longer show "matching terms" after I upgraded to Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277837#M83817</link>
      <description>&lt;P&gt;This may be related to your &lt;CODE&gt;history&lt;/CODE&gt; on that Search Head which should be here:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/users/&amp;lt;YourUserName&amp;gt;/search/history/&amp;lt;YourSearchHead&amp;gt;.csv
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It seems that something during your upgrade damaged/deleted this file but perhaps you can restore it from your backup.  You did make a backup of your Search Head before you upgraded, didn't you?&lt;/P&gt;

&lt;P&gt;Also, as the file location implies, you have a different search history depending on which app (context) you have when you search.  It is possible that either you are searching from within a different app.  This is common when some apps are removed during the upgrade process.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 21:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277837#M83817</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-20T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search typeahead no longer show "matching terms" after I upgraded to Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277838#M83818</link>
      <description>&lt;P&gt;These are "matching terms" not matching previous searches. Shouldnt they  be fetched from the index? In 6.2 I can see ..DEBUG SearchOperator: Typeahead ....loadtermsfromlex.  In 6.3 when I put the SearchOperator:Typeahead in debug mode I dont see this "loadtermsfromlex" occurring. Also, to answer your question. I see my searchhead.csv file and it looks fine.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 21:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277838#M83818</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2015-10-20T21:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search typeahead no longer show "matching terms" after I upgraded to Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277839#M83819</link>
      <description>&lt;P&gt;It looks like this bug has already been reported to engineering as:&lt;BR /&gt;
SPL-93222&lt;BR /&gt;
SPL-96621&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 14:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-typeahead-no-longer-show-quot-matching-terms/m-p/277839#M83819</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2015-10-21T14:28:05Z</dc:date>
    </item>
  </channel>
</rss>

