Alerting

Why is Spunk search with index not working?

tcsec2user
Explorer

Spunk search with index not working only "index=_configtracker" index is working

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tcsec2user,

check if your searches are working with other _* indexes (as e.g. _internal.

Then check if you're in violation, in this case only searches on _* indexes are running, the others are blocked, but indexing continues to normally work.

Ciao.

Giuseppe

0 Karma

tcsec2user
Explorer

i have tried with same index="_sl1index" and index="_*sl1index" but its not working

Tags (1)
0 Karma

tcsec2user
Explorer

Screenshot 2022-09-13 164654.png

0 Karma

tcsec2user
Explorer

2.png3.png

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tcsec2user,

are you sure that those indexes are existent and active?

see at [Settings -- Indexes]

Anyway, the index name is strange because _* is a notatiopn for Splunk internal indexes, but I don't know this index that seems to be a custom index.

Ciao.

Giuseppe

0 Karma

tcsec2user
Explorer

How to enable the blocked indexs

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @tcsec2user,

If there's no Violation, indexes cannot be blocked, only enabled or disabled and you can enable or disable an index in [Settings -- indexes] or in the indexes.conf file.

If you're speaking of blocked indexes for the License Violation, the only way is to ask to Splunk Support an unblock code.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...