I'm running Splunk Free and have a data source which has events in the last 24 hours. When I run a search for All Time, event are shown in the index, but when I search for Yesterday I get no results.
The only other thing to note is that I only just created the index the data is in because I am expermenting with a new data source. Not sure if this affects anything.
Anyone got an explanation for this?
View solution in original post
DATETIME_CONFIG = CURRENT
It could have been like this.