Splunk Search

Bug ? search result problem

tardieuxth
Engager

Hello,
We encounter a problem during search.

A search result differ from finding the results expected and not finding anything

the only change is the time period.

From 06:00:00 to 09:00:00 it's finding the result expected but between 06:13:00 to 09:10:00 nothing is find (see screenshots)

link text
link text

0 Karma

Matthias_BY
Communicator

Hi,

i just did had a second look at your screenshots. The first search does have time beginning at 6:13 am and the second search with results starts at 6:00 am. if i review the timeline with the bars of the successful search it can really be that all events have been in the timeframe between 6:00 - 6:13. 😉

alt text

alt text

tardieuxth
Engager

the searched was in course when I did the screenshot 🙂

by working to find out why my search wasn't working, we supposed that there is too much data to index and that it takes longer than expected to be treated.

I'll try in a few hours to see if we are true or not

0 Karma

Matthias_BY
Communicator

Hi Tardieu,

can you copy + paste or upload the info shown in the job inspector?
http://docs.splunk.com/Documentation/Splunk/6.0.3/Knowledge/ViewsearchjobpropertieswiththeJobInspect...

There we should find the cause.

br
Matthias

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...