<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we find the missing events in splunk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/744149#M10880</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275" target="_blank"&gt;@AL3Z&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;did you fix the issue, i am also facing the same issue.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 05:00:57 GMT</pubDate>
    <dc:creator>mshakeb</dc:creator>
    <dc:date>2025-04-15T05:00:57Z</dc:date>
    <item>
      <title>How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673500#M9955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Splunk hasn't captured the 4743 events, indicating computer account deletions that occurred yesterday at 2 pm. Where should we investigate to determine the root cause?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 08:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673500#M9955</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-01-08T08:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673503#M9956</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should run a searh like the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index EventCode=4743&lt;/LI-CODE&gt;&lt;P&gt;if you haven't results, you have to perform two checks:&lt;/P&gt;&lt;P&gt;at first on the Splunk_TA Windows that you're using to ingest logs, to see if this EventCode is ingested or not. maybe there's a white list or a blacklist the filters this EventCode.&lt;/P&gt;&lt;P&gt;if there isn't any filter, see in your Domain Controller if this EventCode is loged on Windows: not al events are logged by default, about this, I cannot help you: you need a Windows specialist.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 09:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673503#M9956</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-08T09:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673505#M9957</link>
      <description>&lt;P&gt;There are several possible causes for that. Starting from wrong permissions on the source side (we don't even know if these are the only events that are not ingested or if you're ingesting any events from the Security journal at all), through input black/whitelisting, to active filtering on HFs/indexers.&lt;/P&gt;&lt;P&gt;Don't get me wrong, but from this thread and other similar ones it looks as if your employer bought Splunk license but didn't invest in either trainings for the staff or maintenance services from your friendly local Splunk partner. And you seem to need it.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 09:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673505#M9957</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-08T09:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673506#M9958</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;we're ingesting logs with these event code, but occasionally, we're not receiving all the logs from the DCs into Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 09:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673506#M9958</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-01-08T09:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673508#M9959</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you saying the usualy events with this EventCode are ingested, but sometimes you lose events?&lt;/P&gt;&lt;P&gt;In this case, analyze if there was some downtime of the Forwarder or of the connection, starting from the period where you're sure that you loosed some events.&lt;/P&gt;&lt;P&gt;If you're sure that there wasn't any downtime, open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 09:22:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673508#M9959</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-08T09:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673513#M9960</link>
      <description>&lt;P&gt;OK. So you have a different problem.&lt;/P&gt;&lt;P&gt;Are you missing any other events?&lt;/P&gt;&lt;P&gt;Are you having connection problems?&lt;/P&gt;&lt;P&gt;Are you getting any errors in _internal?&lt;/P&gt;&lt;P&gt;Are you hitting thruput limits?&lt;/P&gt;&lt;P&gt;Do you ingest all events from the beginning or just current ones?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 10:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673513#M9960</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-08T10:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673514#M9961</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Are you missing any other events?&amp;nbsp;&lt;BR /&gt;Nope only 4743&lt;/P&gt;&lt;P&gt;Are you having connection problems?&amp;nbsp;&lt;BR /&gt;I dnt think so / How to check&lt;/P&gt;&lt;P&gt;Are you getting any errors in _internal?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;How to check ?&lt;/P&gt;&lt;P&gt;Are you hitting thruput limits?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;yes&lt;/P&gt;&lt;P&gt;Do you ingest all events from the beginning or just current ones?&amp;nbsp;&lt;BR /&gt;Yes we are ingesting all events from beginning.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 11:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673514#M9961</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-01-08T11:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673515#M9962</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As seen on previous reply, to troubleshoot this issue, lot more details are required from your side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any changes recently done on those DC systems inputs.conf / apps / addons&amp;nbsp; etc&lt;/P&gt;&lt;P&gt;Lets say you were expecting the 4743 at 5pm yesterday. Pls check if you have events around that time from that particular windows box (search for 4pm to 6pm events from that windows box)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As said in other posts, the good questions will receive good answers. the more details you provide, the more better answers/suggestions we can help you with. Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 11:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673515#M9962</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-01-08T11:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673961#M9967</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;Today, we made modifications to Domain Admin groups, for which we had previously enabled Notables. The issue is that I haven't received any alerts related to it, and the events have not been collected in Splunk yet.&lt;/P&gt;&lt;P&gt;Here is the services snapshot for the Universal Forwarder from that domain controller:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unnamed.png" style="width: 495px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28876i88E3E8C4DE7233BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="unnamed.png" alt="unnamed.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Do we need to make any changes pls let me know&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 16:30:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673961#M9967</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-01-11T16:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673986#M9969</link>
      <description>&lt;P&gt;OK. So modifications to Domain Admins group is reflected with different events that 4743. So you seem to have a different problem than just losing one particular eventid.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 21:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/673986#M9969</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-11T21:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/744149#M10880</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275" target="_blank"&gt;@AL3Z&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;did you fix the issue, i am also facing the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 05:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/744149#M10880</guid>
      <dc:creator>mshakeb</dc:creator>
      <dc:date>2025-04-15T05:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find the missing events in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/744151#M10881</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/167809"&gt;@mshakeb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please, don't attach your request to another one, even if on the same topic, open a new question.&lt;/P&gt;&lt;P&gt;In this way, you'll have more choices to describe your requirements and to receive an answer.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 06:40:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-find-the-missing-events-in-splunk/m-p/744151#M10881</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-04-15T06:40:19Z</dc:date>
    </item>
  </channel>
</rss>

