Splunk Dev

Splunk Indexed Data Mysteriously Disappears

johnboldt
Explorer

We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...