Deployment Architecture

Cant search real time and last 15 min on search head

xisura
Communicator

Hi Newbie here,

I setup a distributed search,and it successfully run, but when i search realtime (realtime 5min or 30mins) on search head it didnt show any results, i changed it to last 15 mins but no results again, I change it to all time then it shows all result and its updated, i dont know why theres no result on realtime in my search head,

Please help,
xisura

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

View solution in original post

0 Karma

xisura
Communicator

hi @damien ,its now working,your right the machines time are not sync , so i config it and test it again and its now working thanks!! 😉

0 Karma

xisura
Communicator

just to test if there are realtime events,i run realtime search in the indexer yes its working,but in the searchhead no, i will check if their time are sync....

0 Karma

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

0 Karma

xisura
Communicator

when i perform non-realtime search like last 15min it shows no. of events (0 of 10,000 events matched) so no events display,but when i used all-time and used the same search query it shows all the events

0 Karma

Damien_Dallimor
Ultra Champion

What happens if you perform a non-realtime search over the last 15 minutes ? See any events ?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...