Aight so, an admittal if you will. I have been ignoring the fact that all the timestamps are in Zulu time. Therefor, some of what I've claimed is incorrect. So taking the time conversion into account in the below response: ./splunk list monitor Shows all the files that should be monitored, are. ./splunk list inputstatus Shows all the files as before.. the small, less active ones are type = finished reading. The larger, problematic ones are type = open file. All are 100%. Re-running the Query, again for the past 24 hours I now have 4 empty hours (Z -> CDT; 2AM, 3AM, 4AM and 7AM), grepping the log file as before for a timestamp that's missing from SC. So far the first three missing hours: 2, 3, and 4AM are indeed empty from the log file. 7am however has events after searching randomly for, 07:10, 07:34, 07:45..many events. So I have a question out to the networking team to verify there are events/alerts in the local log storage on a device from the group that sourced the missing data. Still waiting for a response from networking.
... View more