Getting Data In
Highlighted

Why don't I have access to source=*metrics.logs at certain hours?

Engager

In standalone environment why my splunk enterprise don't have "source=*metrics.logs " at certain hours.

0 Karma
Highlighted

Re: Why don't I have access to source=*metrics.logs at certain hours?

Builder

Did you try with index and sourcetype in your search...

index=_internal sourcetype=splunkd source=*metrics.log

0 Karma
Highlighted

Re: Why don't I have access to source=*metrics.logs at certain hours?

Path Finder

Possibly your _internal index size is not big enough to hold all the days data and it is rolling off?

0 Karma