Splunk Search

Why are indexed real-time searches not returning results?


I have a Splunk Enterprise cluster (version 8.1.3) that for some reason, is not returning any results for indexed real-time searches, but regular searches and regular real-time searches work just fine.

When I have my search app configured with indexed_realtime_use_by_default = false, my real time searches return fine. When indexed_realtime_use_by_default is true, it returns no data for the same search.

If I change the search from a real time search to any sort of historical search, I also get search results, including over the same time period my real time search is running.

Does anyone have any suggestions what I should look into?

Labels (1)
0 Karma

Path Finder

Maybe there is a problem in your index time field extractions. 

0 Karma


@BahadirS Thanks! I've looked at the values of _time and _indextime on those events and it looks correct to me... Is there someplace else I should check?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...