Splunk Search

Splunk has not returned event in the result two weeks ago but now returns it. How is that possible?

net1993
Path Finder

Hello
I have a saved search that is running every month at 1st day. The search is not new and has been working a long time. The problem is that for the last run, it has returned count of 107 events instead of 108 for a specific date(2019-07-10). The search is running wiith timerange of Last month.
I start to analyze today and I wanted to check first what happens if I run the search now and after I did that I found out that the search returns now 108 events which is correct so what things could have gone wrong at 01.08 so that splunk has not returned 1 event?
We have checked index time of the events and are ok. We have checked that the indexers have not been down from a long time.
It is a cluster solution with 4 indexers + 1 new indexer which has been installed somewhere in july(can that have messed something?)
Splunks task is simply to return all data according to the search, so if Splunk has made error, can it be trusted?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...