Splunk Search

Splunk searches not yeilding data results for months

aecord
New Member

Hello, I am a splunk newby who started using splunk at my job to build dashboards for a call center setting. Since april 3 though, specific searches have not yielded results. Its as if our server stopped keeping record of the data. The only searches that do work are ones involving real time information, For example: how many calls we have waiting. Any search that needs to reverence historical infor from either the day before/hour before/minute before no longer works. Does anyone have a possible reason why this might be taking place or can someone point me in the direction of some resources that might help?

Tags (1)
0 Karma

swong_splunk
Splunk Employee
Splunk Employee

Sounds like the data is being deleted due to either the size of the index or frozenTimePeriodInSecs. You can check the data time stamp from the UI under settings, Indexes. Check the index and the earliest event.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...