Knowledge Management

Data Model: Change Root Event Constraint returns 0 results.

Tim_1
Path Finder

Hi all,

I've been working on a Data Model, and have a root event with constraint:
index=test_index

Now, when I change the constraint to:
index=prod_index

In the preview, nothing gets returned.

1) Can you change the index in the constraint?
2) Also, can you have wildcard in the constrain such as index="*_index"?

There is data in both indexes and I'm using Splunk Enterprise 6.4.2.

Thanks all.

0 Karma

andre_tucker
Path Finder

Yes I believe if your constraints are required and come in as null then the preview will take this into account and not show results. Please test by changing the required field to optional. If that does not work let me know.

0 Karma

andre_tucker
Path Finder

Are there any fields that you are specifying as "required" that are null in your prod index?

0 Karma

Tim_1
Path Finder

@andre_tucker, yes there were.
Does previewing the data when changing the constraint also apply the required attributes as well then?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...