Splunk Search

Some logs were missed by splunk in search index

chandrajay
New Member

While using splunk, we are missing some events in search index. There is no repeated behavior of this kind but they are missing very rarely causing to create in-correct details.

We get beginning of a process logs but we are not receiving the ended process logs, so splunk is showing in-correct details about run time of some process. The same process was properly logged 99% of the time but missing 1%.

Is there a way to fix this issue?

Splunk version: 6.4.3

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...