Splunk Search

Some logs were missed by splunk in search index

chandrajay
New Member

While using splunk, we are missing some events in search index. There is no repeated behavior of this kind but they are missing very rarely causing to create in-correct details.

We get beginning of a process logs but we are not receiving the ended process logs, so splunk is showing in-correct details about run time of some process. The same process was properly logged 99% of the time but missing 1%.

Is there a way to fix this issue?

Splunk version: 6.4.3

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...