Splunk Dev

can't see all the event of an index anymore

splunkLPN
Path Finder

If I search | eventcount summarize=false index=index3 the answer is count : 32339388
If I search index=index3 182154 event events are count with empty days 42 days before the last days.

I've made 2 changes before to have this behavior :

  • upgrade to 7.1
  • go from a free license to a dev licence on my lab machine.

of course i'm on "all-time" period (or hope to be, because it's look like I'm not)

thank's for your help 🙂

Tags (2)
0 Karma
1 Solution

splunkLPN
Path Finder

OK I've found the limit : "Search auto-finalized after disk usage limit (0MB) reached. "

View solution in original post

0 Karma

splunkLPN
Path Finder

OK I've found the limit : "Search auto-finalized after disk usage limit (0MB) reached. "

0 Karma

p_gurav
Champion

Did you run both the query for all time?

0 Karma

splunkLPN
Path Finder

Thank's. Yes. I did it with the web interface. Is there a SPL command to include all time period ?

0 Karma

skoelpin
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...