Monitoring Splunk

Local data added in splunk server getting deleted

SathyaNarayanan
Path Finder

Hi,

I have uploaded 15 csv files in splunk from local by Add data option and view in the search.

After some days in 15 files, 4 files got deleted, I re-uploaded the files once again but still it got deleted in few days.

I couldn't find the reason. i searched whether the data got deleted in _audit but i couldn't find anything.

Thanks in Advance

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi SathyaNarayanan,
check the retention of your index and verify if events are in the retention period, maybe they are outside!

Bye.
Giuseppe

0 Karma

SathyaNarayanan
Path Finder

I checked that too, it is five years. if the retention period was problem other csv also should have been deleted

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...