In standalone environment why my splunk enterprise don't have "source=*metrics.logs " at certain hours.
Possibly your _internal index size is not big enough to hold all the days data and it is rolling off?
Did you try with index and sourcetype in your search...
index=_internal sourcetype=splunkd source=*metrics.log