Deployment Architecture

Cant search real time and last 15 min on search head

xisura
Communicator

Hi Newbie here,

I setup a distributed search,and it successfully run, but when i search realtime (realtime 5min or 30mins) on search head it didnt show any results, i changed it to last 15 mins but no results again, I change it to all time then it shows all result and its updated, i dont know why theres no result on realtime in my search head,

Please help,
xisura

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

View solution in original post

0 Karma

xisura
Communicator

hi @damien ,its now working,your right the machines time are not sync , so i config it and test it again and its now working thanks!! 😉

0 Karma

xisura
Communicator

just to test if there are realtime events,i run realtime search in the indexer yes its working,but in the searchhead no, i will check if their time are sync....

0 Karma

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

0 Karma

xisura
Communicator

when i perform non-realtime search like last 15min it shows no. of events (0 of 10,000 events matched) so no events display,but when i used all-time and used the same search query it shows all the events

0 Karma

Damien_Dallimor
Ultra Champion

What happens if you perform a non-realtime search over the last 15 minutes ? See any events ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...