I understand that I should obtain results if I also consult only specifying the sourcetype and the rest of the search criteria, but I don't know why it does not bring results, how could I solve it?
there are results
index = myindex sourcetype = my sourcetype
no results
sourcetype = my sourcetype
If index= is not specified in the search then Splunk uses the default indexes, if any, for your role. If myindex is not among the default indexes then there will be no results.
If index= is not specified in the search then Splunk uses the default indexes, if any, for your role. If myindex is not among the default indexes then there will be no results.
You are absolutely right, I did the sourcetypes query of the index main and it returned results.
When taking any sourcetype from any other index there are no results.
In conclusion: It only brings information when consulting only with sourcetype but from index = main
where do I manage those indexes? I also need to be able to search only specifying the sourcetype only
The default index list is managed by admins at Settings->Roles.
Searching only by sourcetype is inefficient. Index and time are the best ways to narrow the scope of a search. Sourcetype and host are next-best.
If you know the data resides in a particular index then specifying that index is faster than having Splunk search all of your default indexes (all but one of which will have no data).