<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lost AWS events after ingestion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748359#M118928</link>
    <description>&lt;P&gt;index=aws but i ended up logging onto both servers and moving the whole index from "old" Splunk over to "new" Splunk&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 14:55:01 GMT</pubDate>
    <dc:creator>vishalduttauk</dc:creator>
    <dc:date>2025-06-19T14:55:01Z</dc:date>
    <item>
      <title>Lost AWS events after ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/698877#M115834</link>
      <description>&lt;P&gt;I am in the middle of a Splunk migration. One of the tasks is to moved data from some sourcetypes onto the new servers using the&amp;nbsp;| collect index=aws sourcetype=* command.&lt;/P&gt;
&lt;P&gt;The numbers added up after running checks. I run the same checks again a day later and the numbers no longer match up.&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%" height="47px"&gt;Source 1 -&amp;gt;&lt;/TD&gt;
&lt;TD width="20%" height="47px"&gt;Old Splunk&lt;/TD&gt;
&lt;TD width="20%" height="47px"&gt;New Splunk&lt;/TD&gt;
&lt;TD width="20%" height="47px"&gt;Source 2 -&amp;gt;&lt;/TD&gt;
&lt;TD width="10%" height="47px"&gt;Old Splunk&lt;/TD&gt;
&lt;TD width="10%" height="47px"&gt;New Splunk&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;August&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;12,478,853&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;12,478,853&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="10%" height="25px"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;26,171,911&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="10%" height="25px"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;26,171,911&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24 hours later&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;Source 1 -&amp;gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;Old Splunk&lt;/TD&gt;
&lt;TD width="20%"&gt;New Splunk&lt;/TD&gt;
&lt;TD width="20%"&gt;Source 2 -&amp;gt;&lt;/TD&gt;
&lt;TD width="10%"&gt;Old Splunk&lt;/TD&gt;
&lt;TD width="10%"&gt;New Splunk&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;12,478,853&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;12,477,696&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="10%"&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;26,171,911&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="10%"&gt;3,001,183&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've set the following stanza within the indexes.conf file on the deployment server. Also the index only contains 22gb of data. Can you help?&lt;/P&gt;
&lt;P&gt;[aws]&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;coldPath = $SPLUNK_DB\$_index_name\colddb
enableDataIntegrityControl = 0
enableTsidxReduction = 0
homePath = $SPLUNK_DB\$_index_name\db
maxTotalDataSizeMB = 512000
thawedPath = $SPLUNK_DB\$_index_name\thaweddb
frozenTimePeriodInSecs=94608000&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 12 Sep 2024 14:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/698877#M115834</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2024-09-12T14:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lost AWS events after ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748193#M118902</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228513"&gt;@vishalduttauk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you provide the complete search that you used for migrating the data from one server to other?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 07:40:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748193#M118902</guid>
      <dc:creator>tej57</dc:creator>
      <dc:date>2025-06-18T07:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Lost AWS events after ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748359#M118928</link>
      <description>&lt;P&gt;index=aws but i ended up logging onto both servers and moving the whole index from "old" Splunk over to "new" Splunk&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 14:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748359#M118928</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2025-06-19T14:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Lost AWS events after ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748374#M118929</link>
      <description>&lt;P&gt;Most probably your data was rolled out due to either retention period or index/volume size limits.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 20:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Lost-AWS-events-after-ingestion/m-p/748374#M118929</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-19T20:39:00Z</dc:date>
    </item>
  </channel>
</rss>

