As has been hinted at, missing log data is often a symptom of source, indexer, and/or search head not agreeing on the time standard. If your data is consistently missing for the most recent hour, but then appears to back fill, you might find that there is a discrepancy causing the data you search for to be forward-dated by an hour. That happens when (for instance) the indexer is working to GMT and the source is working to BST and the indexer is taking its time reference from the log entry, not the current clock. (In that case the logs will be forward-dated by an hour, and any search up to the present moment will not find it.
If, however, you consistently lose data during one specific hour of the day I would look to some daily task or other interrupting the log generation or forwarding on the host. (Premature deletion of logs by a daily process causing the data to go missing until the log service is restarted for instance, or something actually stalling the log generator and restarting it an hour later.)
... View more