<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: complete logs are not in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84844#M17646</link>
    <description>&lt;P&gt;for example i will search for 'isnwmkflbndd15eyhwtn0rk1' and splunk will return this snippet,&lt;/P&gt;

&lt;P&gt;2012-03-06 08:50:04,177 [41] [sid=isnwmkflbndd15eyhwtn0rk1] INFO OfferHistoryProcessor - Sending request to service bus...&lt;/P&gt;

&lt;P&gt;and that's all there is when i show source in splunk. when in reality the actual log has a lot more information in it. &lt;/P&gt;

&lt;P&gt;it looks like splunk is setting a timestamp for the complete logs for some date in the future and i'll get all the results i'm looking for if i set my time range to all time.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2012 17:04:58 GMT</pubDate>
    <dc:creator>jhahn101</dc:creator>
    <dc:date>2012-03-06T17:04:58Z</dc:date>
    <item>
      <title>complete logs are not in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84842#M17644</link>
      <description>&lt;P&gt;We’re having an issue with splunk where our logs are only being partially indexed.  are there any logs in splunk where we can check to see what was actually indexed or some way to force a reindexing of said logs.  &lt;/P&gt;

&lt;P&gt;Basically when we search for specific parts of the log it does not show up in the splunk search results, but when we look at the actual log files we see the information we are looking for is there.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 22:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84842#M17644</guid>
      <dc:creator>jhahn101</dc:creator>
      <dc:date>2012-03-05T22:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: complete logs are not in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84843#M17645</link>
      <description>&lt;P&gt;So, it sounds like the logs 'are' there, but your search term isn't catching.  Can you share 1) what you are searching on 2) what you are expecting to get and 3) what you are actually getting?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 11:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84843#M17645</guid>
      <dc:creator>bobbyfaber</dc:creator>
      <dc:date>2012-03-06T11:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: complete logs are not in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84844#M17646</link>
      <description>&lt;P&gt;for example i will search for 'isnwmkflbndd15eyhwtn0rk1' and splunk will return this snippet,&lt;/P&gt;

&lt;P&gt;2012-03-06 08:50:04,177 [41] [sid=isnwmkflbndd15eyhwtn0rk1] INFO OfferHistoryProcessor - Sending request to service bus...&lt;/P&gt;

&lt;P&gt;and that's all there is when i show source in splunk. when in reality the actual log has a lot more information in it. &lt;/P&gt;

&lt;P&gt;it looks like splunk is setting a timestamp for the complete logs for some date in the future and i'll get all the results i'm looking for if i set my time range to all time.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84844#M17646</guid>
      <dc:creator>jhahn101</dc:creator>
      <dc:date>2012-03-06T17:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: complete logs are not in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84845#M17647</link>
      <description>&lt;P&gt;Is this a multi-line log?&lt;BR /&gt;
If it is, check out the documentation on &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.1/Data/Indexmulti-lineevents"&gt;multi-line&lt;/A&gt; events.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/complete-logs-are-not-in-splunk/m-p/84845#M17647</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-03-06T17:47:20Z</dc:date>
    </item>
  </channel>
</rss>

