I'm indexing some syslog data from UDP. I'm using a transform on the data to set the sourcetype of data from certain hosts like this:
That works just fine. When I do a search by host, I see the data as expected, and the sourcetype is vmware_syslog. So, for example, this search returns 30,399 results:
This search, however, returns none:
It's strange, because on my search homepage, I can page through the source types, find vmware_syslog, and click on it to do a search, but I still get no results.
I just want to make sure I'm not missing something before I file a support case.
asked 18 Feb '11, 22:29
I went ahead and filed a support request
What is the count for your sourcetype vmware_syslog on the summary page? 0?
Judging by your
P.S. It looks like
answered 19 Feb '11, 00:54