Not finding the events you're looking for?
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Not finding the events you're looking for?
If you're searching for events and not finding them or looking at a dashboard and seeing "No result data", there could be a couple of reasons why:
Are you running Splunk Free?
Splunk Free does not support scheduled saved searches or summary indexing. If you're in an app that uses search artifacts created by scheduled searches (for example by including them with the HiddenSavedSearch module), those searches will be run on-demand when you view the dashboard. That may result in longer load times than you experienced in the Enterprise or Enterprise Trial versions.
If an app uses summary indexes, however, the summary index(es) will not be updated in a Free version of Splunk because the job scheduler is unavailable. If an app does not already have an alternative Free view defined, you may see "No Results" in dashboards that were relying on summary indexes.
Saved searches that were previously scheduled are still available, and you can run them manually as required. You can also view, move or modify them in the UI or in savedsearches.conf.
Review this topic about object ownership and this topic about configuration file precedence for information about where Splunk writes knowledge objects such as saved searches.
Was the data added under a different app?
When you add an input to Splunk, that input gets added relative to the app you're in. Some apps, like the *nix and Windows apps that ship with Splunk, write input data to a specific index (in the case of *Nix and Windows, that is the 'os' index). If you're not finding data that you're certain is in Splunk, be sure that you're looking at the right index. You may want to add the 'os' index to the list of default indexes for the role you're using. For more information about roles, refer to the topic about roles in this manual.
This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 View the Article History for its revisions.