Splunk Search

Web intelligence no data in reports

andrey2007
Contributor

I locally index data from apache server.
I can see events for search sourcetype="access_*" and field extraction works but no data in all reports.
Any Ideas?
Thanks
Andrey

Tags (1)
0 Karma

JSapienza
Contributor

And you set "Specify log sources" in step 3 of the App setup to sourcetype=access_* ?

0 Karma

macycron
Explorer

try index=

0 Karma

andrey2007
Contributor

yes i setup to access_combined

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...