I am new to splunk and observing the event count and current size showing a 0, even though we can search on the index and have data . Any insights will be helpful.
hi Giuseppe,
Thanks for the response.
the issue is for both internal and external indexes , the event count and current size is not showing any value. You mentioned the default search path, could you please shed some info on that,may be i can explore that option.
Hi @Namo,
what's the search you runned?
did you inserted the name of the index in your main search or at least index=*?
maybe the index you're using isn't in the default search path, so you don't find anything.
Ciao.
Giuseppe