Splunk Search

Events return blank results

kalilinux0011
New Member

alt text

I don't know what happened,pls look the picture and help me!

thanks very much

0 Karma

AzJimbo
Path Finder

this old problem bit me today.  Go to 'All Fields' and deselect all fields, then close that window.    Once that was settled, I was able to reselect the 'All Fields' option and the Event Viewer repopulated.  Not sure why it worked, but it did and thought I'd share.

Tags (2)
0 Karma

Anantha123
Communicator

Hi,
sorry cant understand Chinese. but can say that the results will be shown 3rd(Statistics) and 4th(Visualisation) tabs.
If you are in "Fast mode" , then you cannot see events . If you want to see the events you have to change to "Verbose Mode".

Hope this helps.

Thanks
Anantha.

0 Karma

kalilinux0011
New Member

blank in "Verbose Mode",other mode is OK
so I can't see the raw data in Verbose Mode

0 Karma

danflannery
New Member

I am having the same issue. In Verbose mode, I am only able to see events under 1 App, which changes randomly. Running the same query under other apps shows the fields on left, but events are blank.

Been having this issue for over a year now and my local Splunk admins cannot seem to help. They think it's a rendering issue with my browser, but I've tried multiple browsers and it behaves the same way on my iPhone as well. Seems to be more of an account-level issue or permissions setting.

0 Karma

JyPl4wNYu7GV1uL
Explorer

I know this is ancient, but I had the same issue with blank results because of this:
https://community.splunk.com/t5/Splunk-Search/What-would-intermittently-cause-less-events-to-return-...

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@kalilinux0011

It would be great if you share some sample event and search to help you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...