For example , i have a sourcetype=abc and data in splunk started missing for this sourcetype from past week . Can i please know how can we find out the root cause
start here:
http://docs.splunk.com/Documentation/Splunk/6.6.2/Troubleshooting/Cantfinddata
hope it helps