Splunk Search

Splunk searches not yeilding data results for months

aecord
New Member

Hello, I am a splunk newby who started using splunk at my job to build dashboards for a call center setting. Since april 3 though, specific searches have not yielded results. Its as if our server stopped keeping record of the data. The only searches that do work are ones involving real time information, For example: how many calls we have waiting. Any search that needs to reverence historical infor from either the day before/hour before/minute before no longer works. Does anyone have a possible reason why this might be taking place or can someone point me in the direction of some resources that might help?

Tags (1)
0 Karma

swong_splunk
Splunk Employee
Splunk Employee

Sounds like the data is being deleted due to either the size of the index or frozenTimePeriodInSecs. You can check the data time stamp from the UI under settings, Indexes. Check the index and the earliest event.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...