Hi,
I have uploaded 15 csv files in splunk from local by Add data option and view in the search.
After some days in 15 files, 4 files got deleted, I re-uploaded the files once again but still it got deleted in few days.
I couldn't find the reason. i searched whether the data got deleted in _audit but i couldn't find anything.
Thanks in Advance
Hi SathyaNarayanan,
check the retention of your index and verify if events are in the retention period, maybe they are outside!
Bye.
Giuseppe
I checked that too, it is five years. if the retention period was problem other csv also should have been deleted