Getting Data In

Event count is showing Zero

Namo
Explorer

I am new to splunk and  observing the event count and current size showing a 0, even though we can search on the index and have data . Any insights will be helpful.

Labels (1)
0 Karma

Namo
Explorer

 hi Giuseppe,
Thanks for the response.
the issue is for both internal and external indexes , the event count  and  current size is not showing any value. You mentioned the default search path, could you please shed some info on that,may be i can explore that option.

Namo_0-1718724000594.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Namo,

what's the search you runned?

did you inserted the name of the index in your main search or at least index=*?

maybe the index you're using isn't in the default search path, so you don't find anything.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...