Splunk Search

Why is Datamodel=Authentication not getting older events?

mlm
Explorer

Hey gents,

 I am very new to splunk but does anyone have an idea why my search from datamodel=authentication not getting older events (say last month or two)? Below is my search string:

| tstats prestats=true summariesonly=true allow_old_summaries=true count from datamodel=Authentication.Authentication where Authentication.app=win* Authentication.action=* by _time, Authentication.action span=10m
| timechart minspan=10m useother=true count by Authentication.action



Any suggestion would be so much appreciated! 


Cheers 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can either disable acceleration, change the summary range and rebuild the summaries (which is not a great idea because you have to rebuild everything from scratch and summaries eat up significant amounts of space) or search without the summariesonly=true option (which will be much more intensive since you'll have to search through all the raw data fitting the dataset conditions.

Both solutions have their pros and cons.

0 Karma

mlm
Explorer

@PickleRick my post got deleted lol.

 

Could you tell me please what the possible change would be to capture those previous months data without tampering what I have now? Basically, I just want to fill the gaps for previous months for reporting purposes 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...