Hi,
When I search for a particular index in my splunk I am not getting any events data. However, when I do search the same index with stats by count I am getting count ass 1430. In both the cases my time range is All-time
index=check30|stats count --> This is giving me output as 1430
index=check30 --> This is not returning any events in search output
I re-started my splunk, cleared the cache and tried multiple browsers but still am unable to get the events in search head o/p. Please suggest what is wrong here as I am fed-up debugging this since morning.
Off the top of my head, would you happen to maybe be searching in Fast mode instead of Smart or Verbose?
I am running the search in smart mode itself
| tstats count where index=check30
This result is1430?
check job_inspector and search.log