Deployment Architecture

Cant search real time and last 15 min on search head

xisura
Communicator

Hi Newbie here,

I setup a distributed search,and it successfully run, but when i search realtime (realtime 5min or 30mins) on search head it didnt show any results, i changed it to last 15 mins but no results again, I change it to all time then it shows all result and its updated, i dont know why theres no result on realtime in my search head,

Please help,
xisura

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

View solution in original post

0 Karma

xisura
Communicator

hi @damien ,its now working,your right the machines time are not sync , so i config it and test it again and its now working thanks!! 😉

0 Karma

xisura
Communicator

just to test if there are realtime events,i run realtime search in the indexer yes its working,but in the searchhead no, i will check if their time are sync....

0 Karma

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

0 Karma

xisura
Communicator

when i perform non-realtime search like last 15min it shows no. of events (0 of 10,000 events matched) so no events display,but when i used all-time and used the same search query it shows all the events

0 Karma

Damien_Dallimor
Ultra Champion

What happens if you perform a non-realtime search over the last 15 minutes ? See any events ?

0 Karma
Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...