What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?
Prefix wildcards might cause performance issues.
Machine data can be in structured and unstructured format.
Field names are case sensitive.
Splunk internal fields contains general information about events and starts from underscore i.e. _ .
How many main user roles do you have in Splunk?