Splunk Search

when consulting for sourcetype it does not bring data

splunkcol
Builder

I understand that I should obtain results if I also consult only specifying the sourcetype and the rest of the search criteria, but I don't know why it does not bring results, how could I solve it?

there are results
index = myindex sourcetype = my sourcetype 

no results
sourcetype = my sourcetype 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If index= is not specified in the search then Splunk uses the default indexes, if any, for your role.  If myindex is not among the default indexes then there will be no results.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If index= is not specified in the search then Splunk uses the default indexes, if any, for your role.  If myindex is not among the default indexes then there will be no results.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkcol
Builder

You are absolutely right, I did the sourcetypes query of the index main and it returned results.

When taking any sourcetype from any other index there are no results.

In conclusion: It only brings information when consulting only with sourcetype but from index = main

0 Karma

splunkcol
Builder

where do I manage those indexes? I also need to be able to search only specifying the sourcetype only

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The default index list is managed by admins at Settings->Roles.

Searching only by sourcetype is inefficient.  Index and time are the best ways to narrow the scope of a search.  Sourcetype and host are next-best.

If you know the data resides in a particular index then specifying that index is faster than having Splunk search all of your default indexes (all but one of which will have no data).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...