Splunk Search

Internal index data and performance data is missing

uagraw01
Motivator

To investigate the issue of missing data in Splunk for a period of 3-4 hours, where gaps were observed in the _internal index as well as in performance metrics like network and CPU data, But still can't able to find out the potential root cause of data missing in Splunk. Please help me what I need to investigate more to find out the potential root cause of the data gap in Splunk.

Gap into the _internal index data

uagraw01_0-1728580827166.png

Network performance data gap is visible

uagraw01_2-1728580878038.png

Gap in the CPU performance data

uagraw01_3-1728580951381.png

 

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

in general there can be two potential root causes:

the server is down,

there's a network or server congestion so, the internal Splunk logs have a minor priority than the other logs.

I don't think tha you can find a root cause in _internal, see the server and network logs.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

With congestion you would have a drop in throughput but you'd have some values if only from local internal inputs. Here you seem to have no data points whatsoever which means that it's probably an all-in-one installation or the whole splunk infrastructure was down.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It looks like service downtime. Especially considering a sudden spike in throughput after a drop - the forwarders were pushing the queued data.

Check your splunkd.log immediately before and after that outage.

0 Karma
Get Updates on the Splunk Community!

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...