<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470578#M132379</link>
    <description>&lt;P&gt;Could the issue be related to bucket settings (Hot&amp;gt;Warm&amp;gt;Cold&amp;gt;Frozen)&lt;/P&gt;

&lt;P&gt;I last ran search @ 1700 last night  host=Linuxhostname  - returned the 6.2 and 6.3 (24 hours) results (Modifiers were for last 30 days)&lt;/P&gt;

&lt;P&gt;I Ran same search @ 0600 It returned 6.3 and 6.4  (Time modifiers set for 30 days)&lt;/P&gt;

&lt;P&gt;Could the issue be bucket freeze?&lt;/P&gt;

&lt;P&gt;I ran  index=_internal sourcetype=splunkd component=BucketMover&lt;BR /&gt;
and saw 27 moves to cold or freeze--- mostly freeze&lt;/P&gt;

&lt;P&gt;Based on the fact that until yesterday- Linux hosts were overrunning indexer with 10,000,000 inputs per 8 hours  This was due to  Issues with the Linux UNIX addon , which has now been disabled.&lt;BR /&gt;
/&lt;BR /&gt;
Question is thawing buckets en-masse advisable?  &lt;/P&gt;

&lt;P&gt;I have been googling-- but want to not use a "poke and hope" method to thaw.  &lt;/P&gt;

&lt;P&gt;I have seen different  methods- including this.&lt;BR /&gt;
&lt;A href="https://splunkonbigdata.com/2019/02/27/retrieving-data-from-archive-state/"&gt;https://splunkonbigdata.com/2019/02/27/retrieving-data-from-archive-state/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thoughts please&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2020 14:09:12 GMT</pubDate>
    <dc:creator>jmasat</dc:creator>
    <dc:date>2020-06-04T14:09:12Z</dc:date>
    <item>
      <title>Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470573#M132374</link>
      <description>&lt;OL&gt;
&lt;LI&gt;There are approximately 1.5 Billion ingested entries from 40 forwarders.&lt;/LI&gt;
&lt;LI&gt;Performing a search with any criteria on Windows hosts lists all events as all-time.&lt;/LI&gt;
&lt;LI&gt;Performing the same search on Linux hosts only returns 24 hours of data, regardless of time/date ranges supplied. Each day the data only covers the last 24.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;What settings could be causing this?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 17:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470573#M132374</guid>
      <dc:creator>jmasat</dc:creator>
      <dc:date>2020-06-08T17:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470574#M132375</link>
      <description>&lt;P&gt;Please share your searches.&lt;BR /&gt;&lt;BR /&gt;
Have you checked the time window settings?  The Windows and Linux servers may have different default values.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 14:49:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470574#M132375</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-03T14:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470575#M132376</link>
      <description>&lt;P&gt;The searches are generic:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;host=*&lt;/CODE&gt;  (all variations of day, date range)  returns one day of Linux and all of the expected windows&lt;BR /&gt;
&lt;CODE&gt;Host=linuxhostname&lt;/CODE&gt;  (all variations of day,date range)  returns one day of Linux  regardless of day/date/range&lt;BR /&gt;
&lt;CODE&gt;host= windowshostname&lt;/CODE&gt;  (all variations of day,date range)  returns all data as expected&lt;/P&gt;

&lt;P&gt;Where are the "time windows settings"?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 22:28:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470575#M132376</guid>
      <dc:creator>jmasat</dc:creator>
      <dc:date>2020-06-03T22:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470576#M132377</link>
      <description>&lt;P&gt;The searches are generic - time/day/range filters applied (60 min, 1 day, 30 days, all-time)&lt;BR /&gt;
host=*  displays all Windows data as expected and returns 1 day of Linux data&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;host=Linuxhostname&lt;/CODE&gt; returns  1 day of Linux data&lt;BR /&gt;
&lt;CODE&gt;host=windowshostname&lt;/CODE&gt;  returns all  data as expected&lt;/P&gt;

&lt;P&gt;"Time window settings" different from MS to Linux? &lt;BR /&gt;
Where is that setting?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 22:51:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470576#M132377</guid>
      <dc:creator>jmasat</dc:creator>
      <dc:date>2020-06-03T22:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470577#M132378</link>
      <description>&lt;P&gt;Time window perhaps is better known as the time picker. It's a drop-down menu to the right of the search box where you tell Splunk what time range to search.  The default setting can be different on each Splunk server.  From your comment I know understand you are not running Splunk on mixed platforms.&lt;/P&gt;

&lt;P&gt;Are your Windows and Linux data stored in different indexes with different retention periods?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 00:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470577#M132378</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-04T00:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why does search only display 24 hours of event data on Linux, but all-time on Windows?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470578#M132379</link>
      <description>&lt;P&gt;Could the issue be related to bucket settings (Hot&amp;gt;Warm&amp;gt;Cold&amp;gt;Frozen)&lt;/P&gt;

&lt;P&gt;I last ran search @ 1700 last night  host=Linuxhostname  - returned the 6.2 and 6.3 (24 hours) results (Modifiers were for last 30 days)&lt;/P&gt;

&lt;P&gt;I Ran same search @ 0600 It returned 6.3 and 6.4  (Time modifiers set for 30 days)&lt;/P&gt;

&lt;P&gt;Could the issue be bucket freeze?&lt;/P&gt;

&lt;P&gt;I ran  index=_internal sourcetype=splunkd component=BucketMover&lt;BR /&gt;
and saw 27 moves to cold or freeze--- mostly freeze&lt;/P&gt;

&lt;P&gt;Based on the fact that until yesterday- Linux hosts were overrunning indexer with 10,000,000 inputs per 8 hours  This was due to  Issues with the Linux UNIX addon , which has now been disabled.&lt;BR /&gt;
/&lt;BR /&gt;
Question is thawing buckets en-masse advisable?  &lt;/P&gt;

&lt;P&gt;I have been googling-- but want to not use a "poke and hope" method to thaw.  &lt;/P&gt;

&lt;P&gt;I have seen different  methods- including this.&lt;BR /&gt;
&lt;A href="https://splunkonbigdata.com/2019/02/27/retrieving-data-from-archive-state/"&gt;https://splunkonbigdata.com/2019/02/27/retrieving-data-from-archive-state/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thoughts please&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 14:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-search-only-display-24-hours-of-event-data-on-Linux-but/m-p/470578#M132379</guid>
      <dc:creator>jmasat</dc:creator>
      <dc:date>2020-06-04T14:09:12Z</dc:date>
    </item>
  </channel>
</rss>

