Splunk Search
Highlighted

Why am do I get no results searching host=hostname, but do get results if I add index=_introspection to the search?

Explorer

I am unable to find host when I use host = hostname as query, but I can find same host when I use index=_introspection host=hostname

host=hostname

index=_introspection host=hostname

0 Karma
Highlighted

Re: Why am do I get no results searching host=hostname, but do get results if I add index=_introspection to the search?

SplunkTrust
SplunkTrust

Your role is not configured to search the _introspection index by default, that's why specifying it explicitly works, but omitting it does not.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

Highlighted

Re: Why am do I get no results searching host=hostname, but do get results if I add index=_introspection to the search?

Explorer

Thank you for your response .I having an admin role.

0 Karma