I installed latest Splunk and added splunkforwarder to index log data. Everything looks fine except that search doesn't return any data without specifying the index name, i.e
sourcetype="jetty"
doesn't work
but
index="app" sourcetype="jetty"
works
Any reason why search doesn't work without the index in the search query?
set default in access control as: index!=_*
Assuming the data exists, this behavior is dependent on the default settings for the role. If you want the "app" index to be searchable by default, just add that index to "Indexes searched by default" for the role in question.
By default only the main index is searched. You can change which indexes are searched by default for a user and/or role in the manager in the web interface, Manager -> Access Controls.
Thanks a lot