Splunk Search

Splunk has not returned event in the result two weeks ago but now returns it. How is that possible?

net1993
Path Finder

Hello
I have a saved search that is running every month at 1st day. The search is not new and has been working a long time. The problem is that for the last run, it has returned count of 107 events instead of 108 for a specific date(2019-07-10). The search is running wiith timerange of Last month.
I start to analyze today and I wanted to check first what happens if I run the search now and after I did that I found out that the search returns now 108 events which is correct so what things could have gone wrong at 01.08 so that splunk has not returned 1 event?
We have checked index time of the events and are ok. We have checked that the indexers have not been down from a long time.
It is a cluster solution with 4 indexers + 1 new indexer which has been installed somewhere in july(can that have messed something?)
Splunks task is simply to return all data according to the search, so if Splunk has made error, can it be trusted?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...