Splunk Search

Data deletion upon start problem

yanivoren
New Member

Hi,
I'm using free edition of splunk server, the problem is that every time I start the splunk server, the data is deleted, I also see it being deleted in the var/lib/splunk folder.
more info: I did not breach the 500 MB limit, indexes.conf is at the default state,
same search query is being executed before restart and after restart with different results (before - finds result, after - doesn't), latest splunk 5.0.1 is used.
TIA

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't know what you're doing. Splunk doesn't delete files on restart, and there's no function that does that other than an explicit clean of the indexes. On the other hand, if the files aren't actually being deleted, perhaps it is simply that your query is time-range specific and you're not getting results shortly after a restart because of that.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...