Hi,
We have a query with below format:
(index=A sourcetype=A1) OR (index=A sourcetype=A2) OR (index=B sourcetype=B1)
Sometimes when this query runs it doesn't return events from one of the Index. But the events are present in Splunk.
Checked the scheduler logs and found that search was delegated and also there were some concurrency limit messages.
Have somebody faced the issue where search runs, but some events are missed.
Splunk 7.1.2
Thanks,
Varun Negi
Show us the actual search and the TimePicker value. Something important has been reduced away in your oversimplified explanation.
When you say "doesn't return events from one of the index" did you mean index
or indexer
? Those might be different problems.
Maybe try
(index=A AND sourcetype=A1 OR sourcetype=A2) OR (index=B sourcetype=B1)