Archive
Highlighted

Splunk Indexed Data Mysteriously Disappears

Explorer

We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?

Tags (1)
0 Karma
Highlighted

Re: Splunk Indexed Data Mysteriously Disappears

Splunk Employee
Splunk Employee

Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.

0 Karma