Splunk Dev

Splunk Indexed Data Mysteriously Disappears

johnboldt
Explorer

We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...