Splunk Search

why is my search not returning any output ?

vmallipe
New Member

Hi There,

I'm pretty new to the splunk. we have 3 physical splunk servers and all the forweders are forwarding to 1 and 2. All of sudden some searchs stopped working and rest are working fine. Dont know where to start from. Any help is much appreciated.

Thanks in Advance.

Tags (1)
0 Karma

Takajian
Builder

Splunk internal log is logging in /$SPLUNK_HOME/var/log/splunk/splunkd.log. Please confirm if there is any error or crash.

0 Karma

mw
Splunk Employee
Splunk Employee

Have you tried running the searches which no longer work against a time frame where they were known to work to see if it's the search or the data?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...