Splunk Search

Displaying logs last x days for every month

Kantsplunk
New Member

Not displaying logs more than the last 3 days. This pattern is the same for the last months as well.

for example.
If I am searching for current 30 days logs, it will display only the last 3 days logs and omit other days. when I increased my timeline to last 4 months. I can see same pattern. todays date, yesterday and day before yesterday's date.

Tags (1)
0 Karma

woodcock
Esteemed Legend

WHAT IS YOUR SEARCH?!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the retention settings for the index you are searching? It's possible the index is too small and data is being frozen after 3 days.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Kantsplunk
New Member

I would like to put my issue once again. when I search logs for the last 3 months, then I can see logs for the current date, yesterday and day before yesterday of all last 3 months, other than that I don't see any logs.
for example.

october, 11, 10 and 9th logs are visible.
September 11,10 and 9th logs are visible.
August 11,10 and 9th logs are visible.

ignoreOlderThan = 300d
recursive = true

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying the problem. Do you mind sharing your query? Do you see gaps in the results as well as on the timeline?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...