Splunk Search

Why does searching "index=cisco_ios sourcetype=cisco:ios" return results, but "sourcetype=cisco:ios" does not?

kiran331
Builder

Hi

I'm not able to search only with sourcetype=cisco:ios, When I do index=cisco_ios sourcetype=cisco:ios, it's working, but why? Is there anything I need to change to make it work?

I'm getting the Cisco-ios logs through syslog.

0 Karma
1 Solution

somesoni2
Revered Legend

For Users/Roles, there is a setting (in Settings->Access Control) which you set the "Indexes searched by Default" when no index is set. Based on your issue, the either you don't have any defaultly searched index OR index cisco_ios is not in that list. So adding that index to your list of indexes searched by default will solve the issue.

Being said that, it's always advisable, from performance perspective, that you specify the index you need to search, to cut down the number of indexes/buckets to be searches.

See this for steps on how to edit user roles from Splunk web
http://docs.splunk.com/Documentation/Splunk/6.4.3/Security/Addandeditroles

View solution in original post

somesoni2
Revered Legend

For Users/Roles, there is a setting (in Settings->Access Control) which you set the "Indexes searched by Default" when no index is set. Based on your issue, the either you don't have any defaultly searched index OR index cisco_ios is not in that list. So adding that index to your list of indexes searched by default will solve the issue.

Being said that, it's always advisable, from performance perspective, that you specify the index you need to search, to cut down the number of indexes/buckets to be searches.

See this for steps on how to edit user roles from Splunk web
http://docs.splunk.com/Documentation/Splunk/6.4.3/Security/Addandeditroles

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...