Splunk Search

search in the training does not return any results

jgmit
New Member

Hi
I started the Fundamentals 1 training a couple a weeks ago. I had to stop until today. So I started up by reviewing search but all my searches result in no results found. Searching had worked fine in my first time a couple of weeks ago.
The search window shows that there is data to search. This data was sample data from the tutorial.
What could have changed in 10 days? What can be done to fix this. Thanks so much!!
Jeff

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried searching All Time? It's possible the sample data is old now and you need a larger search window. It's also possible the data has a short retention time and may be gone completely.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jgmit
New Member

I was suspecting that but when I enter the search tab, it lists in what to search, 239,625 events. But I will try entering the data again. Good practice I guess. Thanks for the quick reply.

0 Karma

mayurr98
Super Champion

also with all time settings, try searching for index=*

0 Karma

jgmit
New Member

Thanks for the quick reply but .. Yes indeed I set it to all time and even tried searching for *

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Then I can only conclude the data is gone and you'll have to start over.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Jeff, I removed your email address from the question. It's not a good idea to include personal information in this public forum.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jgmit
New Member

thanks. Did not realize it was a problem.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...