Whilst leaving a Splunk 6 search page open tailing incoming syslogs (with the default * search query), I realised it wasn't tailing in realtime. I investigated the timeframe options and noticed 'All time (realtime)'; I tried to select it but found no results displayed. What I did get was a progress spinner in the left-hand corner below the search box and an empty search results area!
I left the page open for an hour or so and when I returned I could see a small "Invalid SID" error message below the search box (with no results).
I've only been compiling syslogs from a dozen or so devices for approximately one week, and Splunk's running on a dedicated Linux VM with a huge amount of CPU and RAM - it surprised me that realtime result display doesn't work. The install is essentially OOTB default on 64-bit Ubuntu (from the .deb), aside from the addition of the Modular SNMP app (currently not functional).
... View more