Deployment Architecture

Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events

israelgutierrez
Path Finder

Hi

We have weird behavior, in the Data Summary Screen on the Search Head, we see a Host reporting events, when clic on the host searching for the details, the Search Head shows 0 results

This is happening only with 1 host, other hosts from the same index and same sourcetype didn't present the same issue.

Any Ideas?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Search over all time - could be old data / misrecognized timestamp.

View solution in original post

israelgutierrez
Path Finder

No, no one have those privileges

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...