<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why I'm missing log data in Splunk for one day? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230705#M99008</link>
    <description>&lt;P&gt;Define "suddenly" please.  &lt;/P&gt;

&lt;P&gt;Does this mean that yesterday you had data for 25/04 and 24/04 but today "suddenly" the data no longer appears?&lt;/P&gt;

&lt;P&gt;Or does it mean, you have a gap in your data on 25/04 and 24/04 that you didnt notice until today?&lt;/P&gt;

&lt;P&gt;Possible issues for the 1st scenario:&lt;BR /&gt;
-Bad data retirement/retention policy&lt;BR /&gt;
-Someone used the |delete command&lt;BR /&gt;
-Someone manually erased buckets from the filesystem&lt;BR /&gt;
-Filesystem corruption&lt;/P&gt;

&lt;P&gt;Possible issues for the 2nd scenario:&lt;BR /&gt;
-Network was down&lt;BR /&gt;
-Forwarders were down&lt;BR /&gt;
-Splunk was down&lt;BR /&gt;
-Maintenance to mainframe&lt;BR /&gt;
-Maintenance to anything between mainframe and splunk indexers&lt;BR /&gt;
-etc&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2016 12:55:44 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-05-04T12:55:44Z</dc:date>
    <item>
      <title>How to troubleshoot why I'm missing log data in Splunk for one day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230704#M99007</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have logs coming into Splunk from our Mainframe server for a long time. I noticed that Splunk is suddenly not showing any logs on 25/04/2016 and there were partial results on 24/04.  Although it is working fine now, I still don't see logs for only 25/04.  What might be the possibilities for such discrepancies and is there something I need to check on my end?&lt;/P&gt;

&lt;P&gt;Thank you..&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 09:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230704#M99007</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2016-05-04T09:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I'm missing log data in Splunk for one day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230705#M99008</link>
      <description>&lt;P&gt;Define "suddenly" please.  &lt;/P&gt;

&lt;P&gt;Does this mean that yesterday you had data for 25/04 and 24/04 but today "suddenly" the data no longer appears?&lt;/P&gt;

&lt;P&gt;Or does it mean, you have a gap in your data on 25/04 and 24/04 that you didnt notice until today?&lt;/P&gt;

&lt;P&gt;Possible issues for the 1st scenario:&lt;BR /&gt;
-Bad data retirement/retention policy&lt;BR /&gt;
-Someone used the |delete command&lt;BR /&gt;
-Someone manually erased buckets from the filesystem&lt;BR /&gt;
-Filesystem corruption&lt;/P&gt;

&lt;P&gt;Possible issues for the 2nd scenario:&lt;BR /&gt;
-Network was down&lt;BR /&gt;
-Forwarders were down&lt;BR /&gt;
-Splunk was down&lt;BR /&gt;
-Maintenance to mainframe&lt;BR /&gt;
-Maintenance to anything between mainframe and splunk indexers&lt;BR /&gt;
-etc&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 12:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230705#M99008</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-04T12:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I'm missing log data in Splunk for one day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230706#M99009</link>
      <description>&lt;P&gt;it is the second scenario, I have a gap in data for those two dates and till now, I don't see the data coming in for those two days until now.&lt;/P&gt;

&lt;P&gt;so assuming the forwarder was down/network was down, how can I get the data for those days into Splunk now?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 13:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-m-missing-log-data-in-Splunk-for-one/m-p/230706#M99009</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2016-05-04T13:01:55Z</dc:date>
    </item>
  </channel>
</rss>

