Knowledge Management

index is not showing 100%

sasankganta
Path Finder

Index=X sourcetype=Y cribl_pipe=Z when I ran for 1week and 24hrs it showed index , sourcetype field with 100%

Index=X sourcetype=Y cribl_pipe=Z when I ran for 2weeks and 1month  index , sourcetype field is not showing up 100% can some please suggest on this.

I'm searching for single index and single sourcetype but for 1week it's showing 100% field value, for 2 weeks it's not showing 100% what can be the issue ?

Tags (1)
0 Karma

sasankganta
Path Finder

How can I identify raw events which are not indexed source tcp:9997 port 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...