<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Indexed Data Mysteriously Disappears in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Indexed-Data-Mysteriously-Disappears/m-p/73442#M1026</link>
    <description>&lt;P&gt;We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2010 09:58:51 GMT</pubDate>
    <dc:creator>johnboldt</dc:creator>
    <dc:date>2010-10-20T09:58:51Z</dc:date>
    <item>
      <title>Splunk Indexed Data Mysteriously Disappears</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Indexed-Data-Mysteriously-Disappears/m-p/73442#M1026</link>
      <description>&lt;P&gt;We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 09:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Indexed-Data-Mysteriously-Disappears/m-p/73442#M1026</guid>
      <dc:creator>johnboldt</dc:creator>
      <dc:date>2010-10-20T09:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexed Data Mysteriously Disappears</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Indexed-Data-Mysteriously-Disappears/m-p/73443#M1027</link>
      <description>&lt;P&gt;Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 10:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Indexed-Data-Mysteriously-Disappears/m-p/73443#M1027</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-10-20T10:54:56Z</dc:date>
    </item>
  </channel>
</rss>

