I have a Splunk Enterprise cluster (version 8.1.3) that for some reason, is not returning any results for indexed real-time searches, but regular searches and regular real-time searches work just fine.
When I have my search app configured with indexed_realtime_use_by_default = false, my real time searches return fine. When indexed_realtime_use_by_default is true, it returns no data for the same search.
If I change the search from a real time search to any sort of historical search, I also get search results, including over the same time period my real time search is running.
Does anyone have any suggestions what I should look into?
Maybe there is a problem in your index time field extractions.