Splunk Search

Why do I get no results when search internal indexes?

vhallan_splunk
Splunk Employee
Splunk Employee

Why does the search index=_internal not return any results?

0 Karma
1 Solution

vhallan_splunk
Splunk Employee
Splunk Employee

Please add the config to your local authorize.conf file to the one below, restart splunk and now try to search

srchIndexesAllowed = ;_

You can find more on this config in the link below

http://docs.splunk.com/Documentation/Splunk/6.0/admin/authorizeconf

View solution in original post

vhallan_splunk
Splunk Employee
Splunk Employee

Please add the config to your local authorize.conf file to the one below, restart splunk and now try to search

srchIndexesAllowed = ;_

You can find more on this config in the link below

http://docs.splunk.com/Documentation/Splunk/6.0/admin/authorizeconf

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...