DevOps & Observability
DevOps, AppDev, and tool-chains, oh my!

We can't see events older than a day in Splunk

gba8912
Explorer

hello,

 

We recently set up Splunk on our system so we are still learning. We have an issue where we are not getting older events in searches. For example: Event id 4625 (failed logon), we can see the event on the same day it happens but the next day, it will not show up. 

A few things I have tried:

1. removed the ignore older that 2d line in the inputs.conf file.

2. checked to make sure we are not over on bucket size.

Any suggestions on configuring this correctly? I can post config info if requested.

Thanks

0 Karma
1 Solution

HoardingIO
Splunk Employee
Splunk Employee

Hello! Thanks for the message. I think you will get a better response in the "Using Splunk" (https://community.splunk.com/t5/Using-Splunk/ct-p/use-splunk and specifically) "Reporting" (https://community.splunk.com/t5/Reporting/bd-p/splunk-reporting) categories here. This section is focused on the Observability Suite.

Chris

View solution in original post

HoardingIO
Splunk Employee
Splunk Employee

Hello! Thanks for the message. I think you will get a better response in the "Using Splunk" (https://community.splunk.com/t5/Using-Splunk/ct-p/use-splunk and specifically) "Reporting" (https://community.splunk.com/t5/Reporting/bd-p/splunk-reporting) categories here. This section is focused on the Observability Suite.

Chris

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...