Splunk Search

Splunk searches not yeilding data results for months

aecord
New Member

Hello, I am a splunk newby who started using splunk at my job to build dashboards for a call center setting. Since april 3 though, specific searches have not yielded results. Its as if our server stopped keeping record of the data. The only searches that do work are ones involving real time information, For example: how many calls we have waiting. Any search that needs to reverence historical infor from either the day before/hour before/minute before no longer works. Does anyone have a possible reason why this might be taking place or can someone point me in the direction of some resources that might help?

Tags (1)
0 Karma

swong_splunk
Splunk Employee
Splunk Employee

Sounds like the data is being deleted due to either the size of the index or frozenTimePeriodInSecs. You can check the data time stamp from the UI under settings, Indexes. Check the index and the earliest event.

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...