I see the host IP 22.214.171.124 with 1000 events in the last 30 minutes. However, when I run the search, the search does not return any events. Why is this? Thank you for any assistance you may provide.
Hello @vr2312 ,
I am in an admin role. This data is coming in via syslog and coming in through an networking index which I am not sure where that is configured because I don't see it under the indexes.
@rajindurbal You can probably duplicate the inputs.conf and forward it to another index to check if data is being received. I assume you cannot see the mentioned index in the indexes.conf under the IDXs ?