Splunk Search

Splunk searches not yeilding data results for months

aecord
New Member

Hello, I am a splunk newby who started using splunk at my job to build dashboards for a call center setting. Since april 3 though, specific searches have not yielded results. Its as if our server stopped keeping record of the data. The only searches that do work are ones involving real time information, For example: how many calls we have waiting. Any search that needs to reverence historical infor from either the day before/hour before/minute before no longer works. Does anyone have a possible reason why this might be taking place or can someone point me in the direction of some resources that might help?

Tags (1)
0 Karma

swong_splunk
Splunk Employee
Splunk Employee

Sounds like the data is being deleted due to either the size of the index or frozenTimePeriodInSecs. You can check the data time stamp from the UI under settings, Indexes. Check the index and the earliest event.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...