Splunk Search

I see events in the data summary for a host. However, when I search, I don't see any data. How do I see it?

rajindurbal
Path Finder

I see the host IP 1.2.3.4 with 1000 events in the last 30 minutes. However, when I run the search, the search does not return any events. Why is this? Thank you for any assistance you may provide.

Tags (1)
0 Karma

vr2312
Contributor

Hello @rajindurbal

Please ensure your account/role has the privileges to search for the index/host.

0 Karma

rajindurbal
Path Finder

Hello @vr2312 ,

I am in an admin role. This data is coming in via syslog and coming in through an networking index which I am not sure where that is configured because I don't see it under the indexes.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should post your query

0 Karma

vr2312
Contributor

@rajindurbal You can probably duplicate the inputs.conf and forward it to another index to check if data is being received. I assume you cannot see the mentioned index in the indexes.conf under the IDXs ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is your search?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...