Splunk Search

why is my search not returning any output ?

vmallipe
New Member

Hi There,

I'm pretty new to the splunk. we have 3 physical splunk servers and all the forweders are forwarding to 1 and 2. All of sudden some searchs stopped working and rest are working fine. Dont know where to start from. Any help is much appreciated.

Thanks in Advance.

Tags (1)
0 Karma

Takajian
Builder

Splunk internal log is logging in /$SPLUNK_HOME/var/log/splunk/splunkd.log. Please confirm if there is any error or crash.

0 Karma

mw
Splunk Employee
Splunk Employee

Have you tried running the searches which no longer work against a time frame where they were known to work to see if it's the search or the data?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...