Getting Data In

Spath queries return no results. How to troubleshoot?

bbegyperkspot
Explorer

I have a Json formatted log. Splunk shows my fields just fine. If I click one of my fields to filter by that field, Splunk copies my values into the search box. Suddenly today, this search returns zero results.

How do I start debugging this?

Tags (2)
0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

Use the Job Inspector

If your search returns an error you'll see this
alt text

If you don't get an error, you can get to the job inspector from the Job menu dropdown:
alt text

Then scroll down to messages and you'll find information on debugging.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...