Splunk Search

no results found?

TISKAR
Builder

Hey Splunkers:

I indexed my data, and I worked quietly, but today I ran the same query, output is : "no results found"

source="lightsaber_bis2.csv" host="PC" index="index3" sourcetype="csv"

Splunk: Splunk Entreprise.

Can you Help please.

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

Try changing the time range in Splunk search bar.
It's possible that you indexed the data with old timestamps and searching for latest.

Just try setting timerange to "all time" and run the search again

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Try changing the time range in Splunk search bar.
It's possible that you indexed the data with old timestamps and searching for latest.

Just try setting timerange to "all time" and run the search again

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

TISKAR
Builder

Thank you for your respense:

I checked, it's all temp, I loaded the data by creating another index, but when I restat the server, the event going from 11000 event to 0 event

0 Karma

renjith_nair
Legend

Check the "frozenTimePeriodInSecs" property for the index on which this is imported. This defines the data retiring policy for the index (events older than frozenTimePeriodInSecs value in sec, will get deleted).
By default its value is 188697600 which is 6 years and your data may be older that that.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

TISKAR
Builder

Thank you for your respense:

I checked, it's all temp, I loaded the data by creating another index, but when I restat the server, the event going from 11000 event to 0 event

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...