Splunk Search

Search from web UI not working

aksharp
Explorer

We are in a process of setting up new splunk env on CentOS 7. As part of it we have configured 1 search head and 1 indexer server.
We added the indexer to SH in the distributed search section(distsearch.conf), the status of that indexer is "up", Replication status "Successful", healthy status "healthy and No health check failures.
We are using splunkforwarders on our servers to push data to indexers, which is also working fine, i can see data coming from the selected servers in the metrics.log on indexer.
However when i search anything from web UI it gives me "no results found", also in data summary on home page it says "Waiting for results".
Even for index="_internal" there are "no results found".

Can anyone please point me in the right direction if i'm missing anything in the configs here.

Tags (1)
0 Karma

aksharp
Explorer

Thanks for the help! Our indexers were not configured correctly, we updated some some configs and it works now.

0 Karma

adonio
Ultra Champion

start here:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Cantfinddata

please share your findings with the community

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Could it be that your user doesn't have the rights to see the indexes. Check to see that your user has a role that has access to the indexes.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...