Splunk Search

Not displaying Events list when Searching

re24610
New Member

Hello, I have been using splunk for a few months with no issues. Now when I run any search on flashtimeline I can see that events are found but no results are displayed. I can see the pagination where I can click the buttons to view different pages but still no results. I can see all the fields that are found on the left side and I can see the values in them but still no results. I can view the results on the events table, or include a group by in my search I can see them on the results table but still not the events list. This happens on IE 9/8, Chrome, Firefox. Other users are not experiencing this so it seems to be related to my PC/Browser setup. Any idea where to look? I have not made any changes to my PC/Browser settings that I am aware of. Please advise...Thanks.

Tags (1)
0 Karma

cneberg
Explorer

My solution was go into the "All Fields" button on the left of the search results, change Coverage: From "All fields", to something smaller, and hit deselect all. Then run a simple search to make sure things are coming up, then go back and select just specific fields and everything starts to work. My best guess is that at some point - I had it select a huge number of fields, and doing these changes forces it to forget the huge list which fixes the issue.

dewald13
Path Finder

I have a user with this same issue. Was there ever a solution to this?

0 Karma

rameshyedurla
Explorer

Try reinstalling your browsers

0 Karma

re24610
New Member

Thanks for your reply. I have tried un-installing and re-installing flash and that did not help. This is a real limitation to not be able to see any search results. let me know if you find anything out.

0 Karma

hortonew
Builder

Are the graphs using HTML5 or Flash?

If Flash: have you recently updated (or failed to update) flash?

If you haven't considered these, maybe look there first. I haven't experienced the issue, but maybe that will lead you in the right direction.

hortonew
Builder

Very odd... Possibly report that to Splunk and see what they have to say about it.

0 Karma

re24610
New Member

So I was able to determine this only happens with the flashtimeline view. I made an exact copy of this with a different name and it works fine with no issues.

0 Karma

Greg_LeBlanc
Path Finder

It happens for me in both 4.2.2 and 4.3 (Flash/Non-flash). Everyone is using the most up-do-date flash.

0 Karma

Greg_LeBlanc
Path Finder

I am having the same problem. I have an enterprise support ticket open. No work-arund or solution yet. The issues we have are pretty random and don't happen to everyone. We are currently using 4.2.2 but have also upgraded one Seach Head to 4.3 and we can still replicate the problem.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...