Splunk Search

Cannot see data that gets indexed on Summary page

efelder0
Communicator

Recently, I have made changes to my Splunk environment where I created new indexes and assigned multiple data sources to their respective indexes. However, once I index a single data source, that information no longer shows up on the Summary page. i.e. the message, "Waiting for data" appears in the Sources window.

Thoughts?

Tags (3)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

The default view for the Search app summary page is only going to show data from the main index. If you want to see other sources you'll need to add that index as a default for the role of the user you are logging in as. Then you'll see the sources by default instead of having to type in index="whatever".

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

The default view for the Search app summary page is only going to show data from the main index. If you want to see other sources you'll need to add that index as a default for the role of the user you are logging in as. Then you'll see the sources by default instead of having to type in index="whatever".

efelder0
Communicator

I got it, Splunk --> Manager --> Access Controls --> Admin

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can do either but throught the app is probably easiest. Look up the user to see what role they have. Then Manager -> Access Controls -> Roles. Then you'll see a box for 'Indexes searched by default'. Remember this change will apply to all users of that Role.

0 Karma

efelder0
Communicator

would a .conf file need to be changed or a setting w/in the app?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...