Hello guys ,
We`re encountering some log gaps from our proxy into Splunk periodically , so when they`re back , the usecases are not detecting anything for that previous period . How did other companies fixed that ? How is the best way to handle that , when the logs are back , with the minimum of resources ? Do we need to change the start date and end date ( of the log gaps ) manually every time it happens , and run the usecases again ? Or it`s any other more useful solution ?
Thank you!