Getting Data In

Why don't I have access to source=*metrics.logs at certain hours?

aab5272
Engager

In standalone environment why my splunk enterprise don't have "source=*metrics.logs " at certain hours.

0 Karma

dstuder
Communicator

Possibly your _internal index size is not big enough to hold all the days data and it is rolling off?

0 Karma

prakash007
Builder

Did you try with index and sourcetype in your search...

index=_internal sourcetype=splunkd source=*metrics.log

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...