I'm using the splunk version 6.0.5.
I pushed some data containing events of time stamp of last year (04/2014).
However events doesn't show up in the search which has time presets set to "All Time" by default
When I change the presets to Date range some thing like 04/06/2014 to 04/10/2014, the events show up in the search.
Does any body have idea of why the events won't show up in the "All Time" preset?
Just a guess, but do you have permission to search the time range?
Yes. I have access to specify time range. How does this info help?
Sorry for the confusion, let me clarify. If your access level only allows a search for 30 days, you won't be able to see the "All Time" results. The "All Time" results would fall out of the range for the 30 day period.
Hope that helps.