Getting Data In

Why does my sourcetype= search return no results, but pairing with index= does?

craigkleen
Communicator

I re-did some of my data inputs using the same indexes as before to add actual sourcetypes this time. I'm using HWF instead of UF to send data to my indexer. I can now search "index=my_index sourcetype=my_sourcetype", but when my search is just "sourcetype=my_sourcetype", it returns no results over the same time period. Is there a way to fix that? It happened with a couple of sourcetypes, but not all of them.

Tags (2)
1 Solution

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

View solution in original post

MartinMcNutt
Communicator

This may be a security related issue as "Indexes searched by default" will cause the user to only search which he/she is provisioned for.

Check the role that is assigned to the user. Verify that my_index is in that list.

(edit weird post bug)

View solution in original post

craigkleen
Communicator

Yeah, that's it. Thanks!

0 Karma

acharlieh
Influencer

If I had to guess, the sourcetypes that return results are not returning results from my_index, but rather from other indexes? (check out the interesting fields)

Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!