Splunk Dev

When using the Python-SDK, why is Splunk silently returning nothing for some indices?

haffi112
New Member

I'm trying to use the Python SDK to search in Splunk.

However, I can only search on some indices, for others I just get an empty response.

For example, when I use the command

search index=trace

I get a response, but when I use

search index=read

I don't get any response. But if I use the web interface this query works, i.e. my user has rights to search on that index and I am authenticating myself when using the Python-SDK.

Do you have any idea what could explain this? The silent returning of nothing is not helping me.

0 Karma

haffi112
New Member

I have confirmed with an administrator that it is not a problem with access rights as the script shows the same behavior when he authenticates with his user.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...