Splunk Search

Events return blank results

kalilinux0011
New Member

alt text

I don't know what happened,pls look the picture and help me!

thanks very much

0 Karma

AzJimbo
Path Finder

this old problem bit me today.  Go to 'All Fields' and deselect all fields, then close that window.    Once that was settled, I was able to reselect the 'All Fields' option and the Event Viewer repopulated.  Not sure why it worked, but it did and thought I'd share.

Tags (2)
0 Karma

Anantha123
Communicator

Hi,
sorry cant understand Chinese. but can say that the results will be shown 3rd(Statistics) and 4th(Visualisation) tabs.
If you are in "Fast mode" , then you cannot see events . If you want to see the events you have to change to "Verbose Mode".

Hope this helps.

Thanks
Anantha.

0 Karma

kalilinux0011
New Member

blank in "Verbose Mode",other mode is OK
so I can't see the raw data in Verbose Mode

0 Karma

danflannery
New Member

I am having the same issue. In Verbose mode, I am only able to see events under 1 App, which changes randomly. Running the same query under other apps shows the fields on left, but events are blank.

Been having this issue for over a year now and my local Splunk admins cannot seem to help. They think it's a rendering issue with my browser, but I've tried multiple browsers and it behaves the same way on my iPhone as well. Seems to be more of an account-level issue or permissions setting.

0 Karma

JyPl4wNYu7GV1uL
Explorer

I know this is ancient, but I had the same issue with blank results because of this:
https://community.splunk.com/t5/Splunk-Search/What-would-intermittently-cause-less-events-to-return-...

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@kalilinux0011

It would be great if you share some sample event and search to help you.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...