When I am in the search page, and I do a:
source="/my_path/to_file"
Splunk's intellisense, shows me the files that match the pattern of the file that I am typing, and along with each file, it also shows me the number of events associated with each file...
When I choose the file, and I press enter (my timerange is 'All time'), I see no events being returned - why?
I have not customized anything in the configuration files - why is it not returning the events it claims to have indexed? Or is splunk only showing me how many lines it has counted in the file (which is incorrect too)?