We could see only 10 hosts in index=os sourcetype=cpu & index=os source=vmstat. We should get all the unix/linux hosts on the mentioned sourcetype & source. We are using this to generate high cpu utilization, High memory utilization incidents.
Like till August end we are able to see 100+ host for the mentioned source and sourcetype but after August we are not able to see 100+ host like we could see only 10.15,7
Please help me on this
Few preliminary things to check
Splunk documentation has a page that guides customers to troubleshoot similiar issues as you described, like when they don't find the data/events.
"Are you searching for events and not finding them, or looking at a dashboard and seeing "No result data"? Here are a few common mistakes to check."
https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/Cantfinddata