Splunk Search

why is my search not returning any output ?

vmallipe
New Member

Hi There,

I'm pretty new to the splunk. we have 3 physical splunk servers and all the forweders are forwarding to 1 and 2. All of sudden some searchs stopped working and rest are working fine. Dont know where to start from. Any help is much appreciated.

Thanks in Advance.

Tags (1)
0 Karma

Takajian
Builder

Splunk internal log is logging in /$SPLUNK_HOME/var/log/splunk/splunkd.log. Please confirm if there is any error or crash.

0 Karma

mw
Splunk Employee
Splunk Employee

Have you tried running the searches which no longer work against a time frame where they were known to work to see if it's the search or the data?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...