Splunk Search

Cannot see data that gets indexed on Summary page

efelder0
Communicator

Recently, I have made changes to my Splunk environment where I created new indexes and assigned multiple data sources to their respective indexes. However, once I index a single data source, that information no longer shows up on the Summary page. i.e. the message, "Waiting for data" appears in the Sources window.

Thoughts?

Tags (3)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

The default view for the Search app summary page is only going to show data from the main index. If you want to see other sources you'll need to add that index as a default for the role of the user you are logging in as. Then you'll see the sources by default instead of having to type in index="whatever".

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

The default view for the Search app summary page is only going to show data from the main index. If you want to see other sources you'll need to add that index as a default for the role of the user you are logging in as. Then you'll see the sources by default instead of having to type in index="whatever".

efelder0
Communicator

I got it, Splunk --> Manager --> Access Controls --> Admin

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can do either but throught the app is probably easiest. Look up the user to see what role they have. Then Manager -> Access Controls -> Roles. Then you'll see a box for 'Indexes searched by default'. Remember this change will apply to all users of that Role.

0 Karma

efelder0
Communicator

would a .conf file need to be changed or a setting w/in the app?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...