Splunk Search

Events return blank results

kalilinux0011
New Member

alt text

I don't know what happened,pls look the picture and help me!

thanks very much

0 Karma

AzJimbo
Path Finder

this old problem bit me today.  Go to 'All Fields' and deselect all fields, then close that window.    Once that was settled, I was able to reselect the 'All Fields' option and the Event Viewer repopulated.  Not sure why it worked, but it did and thought I'd share.

Tags (2)
0 Karma

Anantha123
Communicator

Hi,
sorry cant understand Chinese. but can say that the results will be shown 3rd(Statistics) and 4th(Visualisation) tabs.
If you are in "Fast mode" , then you cannot see events . If you want to see the events you have to change to "Verbose Mode".

Hope this helps.

Thanks
Anantha.

0 Karma

kalilinux0011
New Member

blank in "Verbose Mode",other mode is OK
so I can't see the raw data in Verbose Mode

0 Karma

danflannery
New Member

I am having the same issue. In Verbose mode, I am only able to see events under 1 App, which changes randomly. Running the same query under other apps shows the fields on left, but events are blank.

Been having this issue for over a year now and my local Splunk admins cannot seem to help. They think it's a rendering issue with my browser, but I've tried multiple browsers and it behaves the same way on my iPhone as well. Seems to be more of an account-level issue or permissions setting.

0 Karma

JyPl4wNYu7GV1uL
Explorer

I know this is ancient, but I had the same issue with blank results because of this:
https://community.splunk.com/t5/Splunk-Search/What-would-intermittently-cause-less-events-to-return-...

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@kalilinux0011

It would be great if you share some sample event and search to help you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...