Reporting

Can't find my last 6 month data

gijoesplunk
New Member

HI everyone,
I usually run report month by month from Januari untill now (and i still have the report), and now i want to get my March dan May data to review it but the no data at all. I tried run search from Januari too and no data, but i can get my June data.
Is there any limitation from splunk to get past data?
FYI, i don't run any archieving.

Tags (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

Start in the monitoring console, in particular the indexes view , this should advise if your indexes are full and if the data has therefore been deleted due to the size limits been reached in the indexes.conf file.

Splunk has no limitations in getting data from a few months or years ago...

0 Karma

gijoesplunk
New Member

where i can get/see in indexes view? If splunk has no limitations in getting data from a few months/years ago,how can i get my previous data back?

0 Karma

gjanders
SplunkTrust
SplunkTrust

If you refer to my link I have linked to the monitoring console documentation and a mention of the indexes page. Also refer to the overview .

0 Karma

gijoesplunk
New Member

Ok, i have found monitoring console.Now what can i do to obtain my previous 6 months data?

0 Karma

gjanders
SplunkTrust
SplunkTrust

Well what does the monitoring console page say ? If it confirms that it has 6 month old data in the index then it is still there.

If it has been removed / the index is out of space then the data has likely been frozen/deleted and you would need to restore from backup and go through a restoration of data...

0 Karma

gijoesplunk
New Member

In Index Details:Instance, The Data Age vs Frozen Age (days) is: 2184, so i will have my data about past 5.9 years isn't it?

0 Karma

gijoesplunk
New Member

Addition Information: Earliest event : 2015-01-19 14:10:16+0700 ; so i think if i search the event from 1 April 2017 to 30 April 2017 i should have the data right?

0 Karma

gjanders
SplunkTrust
SplunkTrust

Assuming your latest event exists in that time range, yes.

The data will exist for 5.9 years if you do not reach the index size limits, reaching the index size limits will also result in the data freezing...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...