Splunk Enterprise

Why am i seeing only 15 Indexes

Kingsmith31
New Member

I am trying to create use cases and searching the indexes but i get index search not found error message. All my logs are not showing up anywhere

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Wait a second. Where are you getting "index not found"? What exactly are you doing so that you get this message? Normal search over a non-existing index simply yields no results as far as I remember.

0 Karma

Kingsmith31
New Member

i got the indexes from existing use cases and searched. but i think i am supposed to add those indexes.

 

Thank you for the insight

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is your role?  The indexes you can see are based on your role.

Can you share the exact error message(s) so are seeing along with the query that caused?  That will help us find the source of the problem.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Kingsmith31
New Member

I am an Admin

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...