Splunk Enterprise

Logs are disappearing

Gnanasekarpj
Observer

Hi All,

Good day...

I have a situation here..

The logs of a particular source-type in a index is getting disappeared.

For ex..  Please find the below results for a query

2021-07-20        0
2021-07-21        10
2021-07-22        232
2021-07-23        3571

After some time like or 24 hrs if I try to run the same search I am getting the below results.

2021-07-20       0
2021-07-21       0
2021-07-22       2
2021-07-23       1524

the logs are being disappeared for the older days.

Note the index max size is set to unlimited and there are no issues with the other source-types under the same source.

Could you please check and let me know what is the issue here..

Labels (1)
0 Karma

Gnanasekarpj
Observer

@kamlesh_vaghela 
Thank you very much for the quick response and Sorry for the delay to your response..

The frozenTimePeriodInSecs is configured as 31536000(365 days)..

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...