Splunk Search

Splunk searches not yeilding data results for months

aecord
New Member

Hello, I am a splunk newby who started using splunk at my job to build dashboards for a call center setting. Since april 3 though, specific searches have not yielded results. Its as if our server stopped keeping record of the data. The only searches that do work are ones involving real time information, For example: how many calls we have waiting. Any search that needs to reverence historical infor from either the day before/hour before/minute before no longer works. Does anyone have a possible reason why this might be taking place or can someone point me in the direction of some resources that might help?

Tags (1)
0 Karma

swong_splunk
Splunk Employee
Splunk Employee

Sounds like the data is being deleted due to either the size of the index or frozenTimePeriodInSecs. You can check the data time stamp from the UI under settings, Indexes. Check the index and the earliest event.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...