Splunk Search

Events return blank results

kalilinux0011
New Member

alt text

I don't know what happened,pls look the picture and help me!

thanks very much

0 Karma

AzJimbo
Path Finder

this old problem bit me today.  Go to 'All Fields' and deselect all fields, then close that window.    Once that was settled, I was able to reselect the 'All Fields' option and the Event Viewer repopulated.  Not sure why it worked, but it did and thought I'd share.

Tags (2)
0 Karma

Anantha123
Communicator

Hi,
sorry cant understand Chinese. but can say that the results will be shown 3rd(Statistics) and 4th(Visualisation) tabs.
If you are in "Fast mode" , then you cannot see events . If you want to see the events you have to change to "Verbose Mode".

Hope this helps.

Thanks
Anantha.

0 Karma

kalilinux0011
New Member

blank in "Verbose Mode",other mode is OK
so I can't see the raw data in Verbose Mode

0 Karma

danflannery
New Member

I am having the same issue. In Verbose mode, I am only able to see events under 1 App, which changes randomly. Running the same query under other apps shows the fields on left, but events are blank.

Been having this issue for over a year now and my local Splunk admins cannot seem to help. They think it's a rendering issue with my browser, but I've tried multiple browsers and it behaves the same way on my iPhone as well. Seems to be more of an account-level issue or permissions setting.

0 Karma

JyPl4wNYu7GV1uL
Explorer

I know this is ancient, but I had the same issue with blank results because of this:
https://community.splunk.com/t5/Splunk-Search/What-would-intermittently-cause-less-events-to-return-...

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@kalilinux0011

It would be great if you share some sample event and search to help you.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...