Getting Data In

Unable to search using Sourcetype

olavo123
Explorer

I have set up a indexer which I also use as an Search Head. I dont have a deployment server so I manually pushed (copied) the apps to the servers to configure the forwarders. The forwarders work just fine and are recognized by the Indexer. And the props as well as input apps work well. And I am able to search for the index data using:

index="test_index" sourcetype=test_sourcetype

All fields defined in props and transform file, show up correctly. These fields also show correctly: host, source and sourcetype. I can see "sourcetype=test_sourcetype" in the events. But I am unable search events using:

sourcetype=test_sourcetype

Any help will be appreciated.

Thanks

Olavo

Tags (1)
0 Karma

MartinMcNutt
Communicator

If you wish to have custom indexes searched by default you must update your Role(s) to include that index as part of the "Indexes searched by default."

  1. Settings
  2. Access controles
  3. Roles
  4. Select Role(s)
  5. Scroll down to "Indexes searched by default"
  6. Add test_index
  7. Click SAVE

jluste
Path Finder

It was my understanding that by default, the user roles only allow searches against index=main. If you wanted to default into other indexes, you'd have to update your roles per app behavior.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Note, this is unrelated to the app but rather controlled by the user's role.

jluste
Path Finder

Yes, that's it. But I thought that this could also be set per application. Do the user roles allow per app settings? (Not an admin)

0 Karma

olavo123
Explorer

Also, I see that I cannot use the fields "host" to perform any searches. I have to use the index= " ", then only other options like "host" , etc become operational.

-Olavo

0 Karma

olavo123
Explorer

I forgot to add that : Both indexer and Forwarders are version 6.1.

Thanks

Olavo

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...