Splunk Search

Splunk has not returned event in the result two weeks ago but now returns it. How is that possible?

net1993
Path Finder

Hello
I have a saved search that is running every month at 1st day. The search is not new and has been working a long time. The problem is that for the last run, it has returned count of 107 events instead of 108 for a specific date(2019-07-10). The search is running wiith timerange of Last month.
I start to analyze today and I wanted to check first what happens if I run the search now and after I did that I found out that the search returns now 108 events which is correct so what things could have gone wrong at 01.08 so that splunk has not returned 1 event?
We have checked index time of the events and are ok. We have checked that the indexers have not been down from a long time.
It is a cluster solution with 4 indexers + 1 new indexer which has been installed somewhere in july(can that have messed something?)
Splunks task is simply to return all data according to the search, so if Splunk has made error, can it be trusted?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...