Hi Good morning.
We have a SH cluster and Indexer cluster. we have received a complain from SOC analyst some of notable events already exists(example last month or a week ago) are missing now or no longer visible on incedent review tab. But, when we try to run again the SPL on that day we got the result.
When we try to search the `notable` | search event_id = "the event id of notable" no result found.
-The storage is big.
-Some complain notable events present last week or last month are no longer visible now or they cannot search, but when we try to run the SPL on that day we got the result.
Can someone guide me, what are the things need to check to pinpoint the cause of this concern we have now. I am new in splunk.