Archive

I see events in the data summary for a host. However, when I search, I don't see any data. How do I see it?

Path Finder

I see the host IP 1.2.3.4 with 1000 events in the last 30 minutes. However, when I run the search, the search does not return any events. Why is this? Thank you for any assistance you may provide.

Tags (1)
0 Karma

Contributor

Hello @rajindurbal

Please ensure your account/role has the privileges to search for the index/host.

0 Karma

Path Finder

Hello @vr2312 ,

I am in an admin role. This data is coming in via syslog and coming in through an networking index which I am not sure where that is configured because I don't see it under the indexes.

0 Karma

SplunkTrust
SplunkTrust

You should post your query

0 Karma

Contributor

@rajindurbal You can probably duplicate the inputs.conf and forward it to another index to check if data is being received. I assume you cannot see the mentioned index in the indexes.conf under the IDXs ?

0 Karma

SplunkTrust
SplunkTrust

What is your search?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!