Splunk Search

Why am I getting 0 results when trying to filter my search by including a specific sourcetype?

szabados
Communicator

I'm facing an issue which I'm simply unable to understand

I ran a search, simply by specifying the index I want to search in like this:

index=my_index

After this, I selected one of the values which were displayed in the top 10 for the sourcetype field, and added it to my search, so I had:

index=my_index sourcetype=my:sourcetype

And then, I got 0 results. I haven't changed the time picker or anything else, and I'm unable to understand why I'm not getting any results. Checking with the metadata command, I have thousands of events with this sourcetype in the index, and Splunk is displaying this sourcetype in the values of the field, but for some reason I can't run a search for it.

Edit:

When I'm not narrowing my search with that filer, I see the events with that particular sourcetype

Edit2:

Searching with:

index=my_index sourcetype=*

is not yielding any events with this problematic sourcetype.
The sourcetype itself if set by props.conf, could this cause any issues?

0 Karma

sundareshr
Legend

Check with your Splunk admin. It is possible to restrict access to specific sourcetypes

http://docs.splunk.com/Documentation/Splunk/6.2.4/Security/Addandeditroleswithauthorizeconf#Search_f...

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Maybe, add double quotes around source type.

index=my_index sourcetype="my:sourcetype"

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

szabados
Communicator

Yes, when I clicked the value from the list, it automatically added, it didn't work either

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Simply when you search for

sourcetype=my:sourcetype

what it returns

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...