Monitoring Splunk

Local data added in splunk server getting deleted

SathyaNarayanan
Path Finder

Hi,

I have uploaded 15 csv files in splunk from local by Add data option and view in the search.

After some days in 15 files, 4 files got deleted, I re-uploaded the files once again but still it got deleted in few days.

I couldn't find the reason. i searched whether the data got deleted in _audit but i couldn't find anything.

Thanks in Advance

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi SathyaNarayanan,
check the retention of your index and verify if events are in the retention period, maybe they are outside!

Bye.
Giuseppe

0 Karma

SathyaNarayanan
Path Finder

I checked that too, it is five years. if the retention period was problem other csv also should have been deleted

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...