Hello,
We encounter a problem during search.
A search result differ from finding the results expected and not finding anything
the only change is the time period.
From 06:00:00 to 09:00:00 it's finding the result expected but between 06:13:00 to 09:10:00 nothing is find (see screenshots)
Hi,
i just did had a second look at your screenshots. The first search does have time beginning at 6:13 am and the second search with results starts at 6:00 am. if i review the timeline with the bars of the successful search it can really be that all events have been in the timeframe between 6:00 - 6:13. 😉
the searched was in course when I did the screenshot 🙂
by working to find out why my search wasn't working, we supposed that there is too much data to index and that it takes longer than expected to be treated.
I'll try in a few hours to see if we are true or not
Hi Tardieu,
can you copy + paste or upload the info shown in the job inspector?
http://docs.splunk.com/Documentation/Splunk/6.0.3/Knowledge/ViewsearchjobpropertieswiththeJobInspect...
There we should find the cause.
br
Matthias