**
A member share this answer and it
works for me
**
Did you define your own index? if so, you will need to add the index to your account's list of indexes to search by default. You can add it by using the Splunk Manager:
1. Go to Users and authentication » Access controls » Roles
2. Select the role you want to change (user, admin, etc.)
3. Add the index to "Indexes searched by default"
To test if that works, run a search for logs with sourcetype of "web_ping" (without specifying the index):
1. sourcetype=web_ping
... View more