<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic All indexed data from earlier than yesterday disappeared. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/All-indexed-data-from-earlier-than-yesterday-disappeared/m-p/251995#M48474</link>
    <description>&lt;P&gt;I was hoping someone could help me here.  We had been ingesting data to an index just fine for weeks, Then all of the sudden all data from yesterday and earlier is missing.  index is currently working fine since that point in time.&lt;/P&gt;

&lt;P&gt;What should I be checking?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2016 18:14:23 GMT</pubDate>
    <dc:creator>Cuyose</dc:creator>
    <dc:date>2016-08-26T18:14:23Z</dc:date>
    <item>
      <title>All indexed data from earlier than yesterday disappeared.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/All-indexed-data-from-earlier-than-yesterday-disappeared/m-p/251995#M48474</link>
      <description>&lt;P&gt;I was hoping someone could help me here.  We had been ingesting data to an index just fine for weeks, Then all of the sudden all data from yesterday and earlier is missing.  index is currently working fine since that point in time.&lt;/P&gt;

&lt;P&gt;What should I be checking?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 18:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/All-indexed-data-from-earlier-than-yesterday-disappeared/m-p/251995#M48474</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2016-08-26T18:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: All indexed data from earlier than yesterday disappeared.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/All-indexed-data-from-earlier-than-yesterday-disappeared/m-p/251996#M48475</link>
      <description>&lt;P&gt;There is no reason that this would ever happen without some sort of outside influence.  Some places that I would look:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Were changes made to your storage? &lt;/LI&gt;
&lt;LI&gt;Verify that indexes.conf is configured properly... &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Indexesconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Indexesconf&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Search "index=* startdaysago=7"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 19:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/All-indexed-data-from-earlier-than-yesterday-disappeared/m-p/251996#M48475</guid>
      <dc:creator>jdonn_splunk</dc:creator>
      <dc:date>2016-08-26T19:26:12Z</dc:date>
    </item>
  </channel>
</rss>

