Splunk Search

action field is not returning any results from all indexes

majid87
Engager

Hello,

Looks like the action field is not returning results for almost all of the indexes. This is only impacting one of the search heads, the action field is working normally in the other search heads ( NOT clustered ). 

 

ex: index=foo ( returns all data ) but when i add index=foo action=allowed returns almost nothing 

 

 

Labels (2)
0 Karma

majid87
Engager

isoutamo

 I meant the default in /etc/apps/app-TA/default. I did not make any changes to it , I'm using the default props/transforms that come with the TA . I know if i need to make any changes on the conf files, i should do it in the local folder , however, in my case, i did not need it . This is impacting all users including the admin. Not sure if this is related to CIM TA , i should also mention the SH has ES installed on it .

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this sounds like you are missing some props.conf (and/or transforms.conf) on this one SH. Just look from those others where that has defined 

splunk btool props list <your sourcetype name> --debug

 Then put those definitions to TA (unless it already is in TA/app) and deploy this to that SH. If those are already defined in separate TA/app, then copy it to that SH.

r. Ismo

0 Karma

majid87
Engager

Thanks isoutamo ,

The issue is not impacting a specific app/TA, it seems to be impacting all indexes. Also, I have compared the two SHs and did not see anything missing from the impacted SH.  I Have run the btool but I have not noticed any issues. 

I should mention that I'm using props/transforms in the default folder and it's been working properly till recently. No changes have been made that I'm aware of.

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

When you are saying “default” folder are you meaning …/etc/system/default and have you changed those? And you haven’t anything in any local folders? 
Is this issue for all users or only for you?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...