Found the issue: We built a standalone SH and copied the $SPLUNK_HOME/etc/apps directory from the SHC to it. Started removing apps on the test server, one at a time, and when we removed one of the Apps and restarted., the searches started to work again. One of our crew found the following in the app the was just removed: [source::stream:Gigamon] EVAL-_time = strptime('timestamp', "%Y-%m-%dT%H:%M:%S,%N") This seems to be the issue. We went back to the SHC and specified a source without removing anything and it pulled data. Not really clear on why that would make a difference, but it does. The main takeaway from this is that a configuration change that had an effect on _time caused this issue.
... View more