Splunk Search

Issue at selection with Time Range picker

krusty
Contributor

Hi,

we use in our environment (indexer cluster, searchhaed/deployment server) Splunk enterprise version 7.1.1.
If we do a search like this

index="test" host="testserver" | sort 0 _time

Over the last 7 days we are not able to show only some events which we select with the time range picker.

Does anybody know why this issue only appears if we use

| sort 0 _time

in our search? If we do not use this, we are able to pick a time range from the picker.
But then the events are not sorted and not really usable.

Tags (1)
0 Karma

HiroshiSatoh
Champion

Is not shortage of resources?
Has an error been output(search.log)?
What happens when you narrow down the fields?

index="test" host="testserver" |fields _time,(fields you use)| sort 0 _time
0 Karma

krusty
Contributor

No error is been reported in any logfile.

If I use

index="test" host="testserver*" 
|  fields _time, raw 
| sort 0 _time

in the search field and search for the last 7 days. I got 10434 events. Then I choose a timeframe from the time picker and at the bottom of the page I didn't see any events, but the page show below the search field that I selected 394 events.

Unfortunately I couldn't upload an example, otherwise you could see what I mean.

0 Karma

HiroshiSatoh
Champion

About 10,000 things will not result in memory shortage. 394 cases are not displayed but are the correct number of cases?

It does not reproduce in my environment. Check the search.log and check warnings and errors.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...