Wondering if there is anyway to recover data that is not reporting within splunk on any alert or dashboard during a time period that splunk had ran out of space and accounts that had ownership became disabled? space issue has been fixed and alerts and dashboards have been given different ownership. splunk forwarder is running on all computers.
Basically when we run an of our alerts and dashboards we don't get any events between the dates of 4/15 and 4/27. Event logs on all computers have events for the time period but splunk isn't pulling them.
... View more