An older splunk instance (6.5.0) was found within my environment running on a windows server 2008r2 host.
The instance was experiencing license breaches which were resolved by pointing the host to our primary license master.
Currently when searching index=* no results are found.
The main index has over 500 million events with data currently flowing into the index.
There are no errors when searching _* indexes
After searching non-internal indexes, check the search.log for the ancient indexer. You may find a message about searches being blocked because of the license violation. If so, then you'll need to contact Splunk for an unlock license.