I have a user that reported he runs a search and the FlashTimeLine fills with over 5,000 events matching his search but the list of events does not display. I get the same results if I run the query but another user sees the events listed. Yesterday, a different user got results displayed; today he does not.
What would cause this to happen?
I never did get a definitive answer to this problem, but there were a couple of things in common to each occurrence of it -- IE was the browser in use. On a few occasions, a few reported seeing the data displayed but when they went back to show me, it did not. One of those did say they used FireFox when the data dispalyed. Here is some of the other factors related to this situation:
What I think was happening was that with so much data to format and display that memory became an issue and the system could not cope with it all; a factor of both the browser and OS. This is a gut call for sure but I could not find anything else to explain it. The problematic search worked OK when we would limit the number of results to a few 100 or less. Fortuantely, that worked for the user needing this search as part of his application management plan.
BTW, this was with Splunk 4.2.1 so none of this is probably really relavent any more. I just noticed this still hanging out there as "open" and chose to follow-up and "close" the issue.
What is the search you are running?