Splunk Search

Splunk has not returned event in the result two weeks ago but now returns it. How is that possible?

net1993
Path Finder

Hello
I have a saved search that is running every month at 1st day. The search is not new and has been working a long time. The problem is that for the last run, it has returned count of 107 events instead of 108 for a specific date(2019-07-10). The search is running wiith timerange of Last month.
I start to analyze today and I wanted to check first what happens if I run the search now and after I did that I found out that the search returns now 108 events which is correct so what things could have gone wrong at 01.08 so that splunk has not returned 1 event?
We have checked index time of the events and are ok. We have checked that the indexers have not been down from a long time.
It is a cluster solution with 4 indexers + 1 new indexer which has been installed somewhere in july(can that have messed something?)
Splunks task is simply to return all data according to the search, so if Splunk has made error, can it be trusted?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...