Splunk Search

I am not able to find a few lines of my data in Splunk

varun99
Path Finder

If I see the file on the server, it has the data. But in splunk, I am able to see all the data except for a few lines. Kindly let me know why it could be happening and what can I do to resolve this kind of behavior.

I am using a simple query like source="filePATH"

0 Karma

obrosch
Path Finder

Do you see your events when you switch to verbose mode and use the raw mode in the events section? Then it is a problem with the line breaking. Maybe you have a regex which filters these events out. This you can find in the props / transforms file.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm betting the line breaking is not working as expected and your searching on data that is present in one event but not the split part. Are you able to narrow your search down for exactly what your looking for rather than just specifying source?

0 Karma

pradeepkumarg
Influencer

Does the missing events differ in any way? Particularly the time stamp on them? Does your TIME FORMAT specification on props.conf for the source type extract correctly for the missing events?

If TIME FORMAT is the issue, you will be able to find the events by searching for a larger time range. Try a few years before and after.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...