<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't search previous data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26577#M5145</link>
    <description>&lt;P&gt;My index indicates i have over 8 million entries but any search i run ends at midnight and will not search any data before the day that i initiate the search.&lt;/P&gt;

&lt;P&gt;I have the time set to "all time" and i'm executing queries that worked properly before.  I can verify it's receiving data and the index is getting bigger, it doesn't seem that it's purging any data i just can't search anything past midnight.  It's not a rolling 24 hours but a hard cutoff at 12.&lt;/P&gt;

&lt;P&gt;Any idea where i can start looking? i've looked at the indexes but nothing there would indicate a time limit and no where else in manager can i find a setting or restriction that would limit me from viewing the data.  I can't find anything in the free documentation that indicates the free version only lets you view that day's data. I'm at a loss as to where to look next.&lt;/P&gt;</description>
    <pubDate>Sun, 08 Aug 2010 21:56:50 GMT</pubDate>
    <dc:creator>smickey</dc:creator>
    <dc:date>2010-08-08T21:56:50Z</dc:date>
    <item>
      <title>Can't search previous data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26577#M5145</link>
      <description>&lt;P&gt;My index indicates i have over 8 million entries but any search i run ends at midnight and will not search any data before the day that i initiate the search.&lt;/P&gt;

&lt;P&gt;I have the time set to "all time" and i'm executing queries that worked properly before.  I can verify it's receiving data and the index is getting bigger, it doesn't seem that it's purging any data i just can't search anything past midnight.  It's not a rolling 24 hours but a hard cutoff at 12.&lt;/P&gt;

&lt;P&gt;Any idea where i can start looking? i've looked at the indexes but nothing there would indicate a time limit and no where else in manager can i find a setting or restriction that would limit me from viewing the data.  I can't find anything in the free documentation that indicates the free version only lets you view that day's data. I'm at a loss as to where to look next.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2010 21:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26577#M5145</guid>
      <dc:creator>smickey</dc:creator>
      <dc:date>2010-08-08T21:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search previous data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26578#M5146</link>
      <description>&lt;P&gt;Are you looking in the 'Global Summary' box when you first connect to the Search App?  I think that reports the total number of events ever processed by your Splunk instance - rather than the current number of events actually archived in your index.&lt;/P&gt;

&lt;P&gt;What is your "frozenTimePeriodInSecs" set to for the index you are trying to search? (ie, your retention policy)  Perhaps you are rolling data out of the database...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2010 21:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26578#M5146</guid>
      <dc:creator>rotten</dc:creator>
      <dc:date>2010-08-09T21:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't search previous data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26579#M5147</link>
      <description>&lt;P&gt;This isn't exactly what was wrong, i had moved my indexes after filling up a drive and the folders were created as root so it never rolled any data between the hot/warm/cold buckets so ended up just losing the data after about 24 hours which is what i'm assuming is the default for rolling over the first bucket&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2010 08:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-search-previous-data/m-p/26579#M5147</guid>
      <dc:creator>smickey</dc:creator>
      <dc:date>2010-08-19T08:14:19Z</dc:date>
    </item>
  </channel>
</rss>

