Deployment Architecture

Cant search real time and last 15 min on search head

xisura
Communicator

Hi Newbie here,

I setup a distributed search,and it successfully run, but when i search realtime (realtime 5min or 30mins) on search head it didnt show any results, i changed it to last 15 mins but no results again, I change it to all time then it shows all result and its updated, i dont know why theres no result on realtime in my search head,

Please help,
xisura

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

View solution in original post

0 Karma

xisura
Communicator

hi @damien ,its now working,your right the machines time are not sync , so i config it and test it again and its now working thanks!! 😉

0 Karma

xisura
Communicator

just to test if there are realtime events,i run realtime search in the indexer yes its working,but in the searchhead no, i will check if their time are sync....

0 Karma

Damien_Dallimor
Ultra Champion

Throwing out some guesses here : Do you actually have events in the 15 min window(based on their index time) ? Are your timestamps being extracted correctly ? Is the index time on the events what you expect ?Are the machines in your architecture time synched ?

0 Karma

xisura
Communicator

when i perform non-realtime search like last 15min it shows no. of events (0 of 10,000 events matched) so no events display,but when i used all-time and used the same search query it shows all the events

0 Karma

Damien_Dallimor
Ultra Champion

What happens if you perform a non-realtime search over the last 15 minutes ? See any events ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...