Hi 🙂
Those definitions are for the host and service performance logs respectively, however the field extraction for 'nagiosevent' is relevant only to nagios.log i.e. sourcetype=nagios
Please try this search over the last 30 days:
index="nagios" "SERVICE NOTIFICATION"
If some events are returned by Splunk, please cut & paste a few sample events here.
Which version of the following apps are you running in your environment:
Splunk
Splunk for Nagios
Nagios
MK Livestatus
All the best,
Luke 🙂
... View more