I see the host IP 1.2.3.4 with 1000 events in the last 30 minutes. However, when I run the search, the search does not return any events. Why is this? Thank you for any assistance you may provide.
Hello @rajindurbal
Please ensure your account/role has the privileges to search for the index/host.
Hello @vr2312 ,
I am in an admin role. This data is coming in via syslog and coming in through an networking index which I am not sure where that is configured because I don't see it under the indexes.
You should post your query
@rajindurbal You can probably duplicate the inputs.conf and forward it to another index to check if data is being received. I assume you cannot see the mentioned index in the indexes.conf under the IDXs ?
What is your search?