Splunk’s best practices is always to use index = in queries. The most obvious reason why he get results from those two indexes is that him user role has defined those two as default indexes which are used if no index word is added to query. For that reason I think that quite many administrators will leave this default as empty so users must tell which indexes they want to use. r. Ismo https://docs.splunk.com/Documentation/Splunk/7.3.3/Admin/Authorizeconf
... View more