Hi all.
I currently experiencing an issue where simple strings won't provide any events while two weeks ago I had. Doesn't matter the time frame. Tried "All time" and still zero events.
So, I wish to see if there is an issue with an index being disable or not working properly.
Is there a search query I can use to find these indexes?
Go to Settings->Indexes to see if the index is disabled. That screen also will tell you if the index has data in it.
It's possible the data you saw 2 weeks ago has aged out or was removed by Splunk to make room for new data in another index (assuming the index shares a volume with another index).
Another possibility is you no longer have access to the index. Searching an index you aren't allowed to read will return zero results rather than an error or warning message.
Doesn't seem like I have this in my settings menu..
The Splunk is not my personal but related to my workplace. Maybe I don't have the proper permissions to view the index menu?
Very possible. And if you can't view that, you may not be allowed to read the index, either. Contact your Splunk admin.