Getting Data In

Spath queries return no results. How to troubleshoot?

bbegyperkspot
Explorer

I have a Json formatted log. Splunk shows my fields just fine. If I click one of my fields to filter by that field, Splunk copies my values into the search box. Suddenly today, this search returns zero results.

How do I start debugging this?

Tags (2)
0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

Use the Job Inspector

If your search returns an error you'll see this
alt text

If you don't get an error, you can get to the job inspector from the Job menu dropdown:
alt text

Then scroll down to messages and you'll find information on debugging.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...