Splunk Search

Why is data summary not displaying?

akankshayadav
Path Finder

When I am click on my data summary, it is not displaying anything just showing

akankshayadav_0-1625829593402.png

Any suggestions?
Thanks.

0 Karma

aliazaad
New Member

if you select index=main for your input 

the problem will be solved

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @akankshayadav,

I haven't your issue in my Splunk, which version are you using?

My only hint is to open a Case To Splunk Support.

Ciao and Happy Easter.

Giuseppe

0 Karma

state_larson_ti
Path Finder

Actually a little more searching and I found the answer here (https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-...). I also on my experimental/learning box (latest version) had enabled (under Settings -> Roles -> Admin -> Indexes) the * (All non-internal indexes) and the _* (All internal indexes) to be default and this immediately allowed data summary to work and see all the indexes.  I can see how, by default, you might not want to have this enabled for the admin account.

I think in courses you do, they may enable this by default for your accounts on non-internal indexes to make it easier for you to configure things, so I had not had to configure it myself.

state_larson_ti
Path Finder

Good Day.  I was curious if you had ever found an answer here.  I noticed the same thing, logged in about 3 days later, and the data had been populated (but not for the data I had put in the day before.  I assume there is a search that populates this data, but it only runs maybe 1/x per day or week.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...