I have a Splunk alert that has been sending false emails. The alert is sent when a string is absent from the application's log. The search itself is actually not finding the log message, which I assume is the reason for the log not being triggered.
This search in Splunk UI: "finished importing data" earliest=-1d@d
Results: no messages found.
But when I search back 7 days, the expected log message appears.
Ex: "finished importing data" earliest=7d@d
Results: messages are returned as expected
Furthermore, I am able to see other messages from the application logs from the last 24 hours in Splunk, but the specific text "finished importing data" only appears when I search for 7 days or greater.
Any ideas why 7-day search would return results but not a 1-day search? Your help is greatly appreciated.
Currently running Splunk version 7.0.1.
... View more