I'm trying to troubleshoot a situation where recently indexed data was searchable up until Splunk was restarted. My license is valid, and I have no hard overage warnings.
I've even tried this on a test box with a fresh install of Splunk. After the restart the indicator on the right side of the home screen under Data went from 50+ million items to "Waiting for data..."
For full disclosure I am trying to index some historical data from 2008. I did add the following to the props.conf located in ..Splunk/etc/system/local.
[default]
MAX_DAYS_AGO = 3650
Also I am running v6.1.2 on Windows.
... View more