DevOps & Observability
DevOps, AppDev, and tool-chains, oh my!

We can't see events older than a day in Splunk

gba8912
Explorer

hello,

 

We recently set up Splunk on our system so we are still learning. We have an issue where we are not getting older events in searches. For example: Event id 4625 (failed logon), we can see the event on the same day it happens but the next day, it will not show up. 

A few things I have tried:

1. removed the ignore older that 2d line in the inputs.conf file.

2. checked to make sure we are not over on bucket size.

Any suggestions on configuring this correctly? I can post config info if requested.

Thanks

0 Karma
1 Solution

HoardingIO
Splunk Employee
Splunk Employee

Hello! Thanks for the message. I think you will get a better response in the "Using Splunk" (https://community.splunk.com/t5/Using-Splunk/ct-p/use-splunk and specifically) "Reporting" (https://community.splunk.com/t5/Reporting/bd-p/splunk-reporting) categories here. This section is focused on the Observability Suite.

Chris

View solution in original post

HoardingIO
Splunk Employee
Splunk Employee

Hello! Thanks for the message. I think you will get a better response in the "Using Splunk" (https://community.splunk.com/t5/Using-Splunk/ct-p/use-splunk and specifically) "Reporting" (https://community.splunk.com/t5/Reporting/bd-p/splunk-reporting) categories here. This section is focused on the Observability Suite.

Chris

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...