Splunk Search

Firewall logs going into separate index: Why the error "Searching - No results found. Try expanding the time range"?

willspk
Engager

Hey everyone,

I've got all our firewall logs going into separate index.

When I perform a search just using the index as a value, for example index="sec-firewalls" the results vary quite a bit.

I get nothing for real-time unless I select all time (real-time). Under relative results I get nothing for today. Nothing for last 15 minutes, last 4 hours etc. Again, the only option that works is All time.

When I'm looking at real-time results, it's about 2hr30m behind.

I am using the Splunk Add-on for Cisco ASA for this index.

Anyone able to assist me with what's happening here?

Thanks,

Will

Labels (1)
Tags (1)
0 Karma

willspk
Engager

Just wanted to add that I'm in directory of the index itself, inside the latest hot directory I can see it's populating with data.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...