Deployment Architecture

Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events

israelgutierrez
Path Finder

Hi

We have weird behavior, in the Data Summary Screen on the Search Head, we see a Host reporting events, when clic on the host searching for the details, the Search Head shows 0 results

This is happening only with 1 host, other hosts from the same index and same sourcetype didn't present the same issue.

Any Ideas?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Search over all time - could be old data / misrecognized timestamp.

View solution in original post

israelgutierrez
Path Finder

No, no one have those privileges

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...