since a while, I cannot see my license usage for more than 7 days.
At the beginning I thought that it was a bad setting on my _internal index that could drop the data over the 7 days period but I was mistaken.
I saw that beyond 7 days, there is no source like in my _internal index
I double verified all my *.conf files but no parameter that could delete data.
My infrastructure consists of:
Do you have any idea that could explain this phenomenon?
thank you in advance
ps: master and SH forwarding data to the indexers
Could you have your license_usage.log checked for data longer than that?
Do you have the most recent data?
Could someone have deleted older data than those 7 days of usage? Do you always have those 7days and no more than that at all times?
Use brook to figure out what retention period you are having on this one. It's too precise so there must be a default retention period for the internal indexes somewhere in you environment.
$SPLUNK_HOME/bin/btool indexes list --debug and check for the internal.