Splunk Search

I am not able to find a few lines of my data in Splunk

varun99
Path Finder

If I see the file on the server, it has the data. But in splunk, I am able to see all the data except for a few lines. Kindly let me know why it could be happening and what can I do to resolve this kind of behavior.

I am using a simple query like source="filePATH"

0 Karma

obrosch
Path Finder

Do you see your events when you switch to verbose mode and use the raw mode in the events section? Then it is a problem with the line breaking. Maybe you have a regex which filters these events out. This you can find in the props / transforms file.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm betting the line breaking is not working as expected and your searching on data that is present in one event but not the split part. Are you able to narrow your search down for exactly what your looking for rather than just specifying source?

0 Karma

pradeepkumarg
Influencer

Does the missing events differ in any way? Particularly the time stamp on them? Does your TIME FORMAT specification on props.conf for the source type extract correctly for the missing events?

If TIME FORMAT is the issue, you will be able to find the events by searching for a larger time range. Try a few years before and after.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...