Hi All, I am new to Splunk and joined this community seeking help. Request you to please help me getting my doubts clear. My Question is 1. When my Splunk is down for an hour, and if i get any adhoc request to get the data for that hour period, so once Splunk is up then what we need to do (restart splunk forwarder?) to restore data or data will be restored by itself or data will be lost. 2. What to do/where to check at instance level when i am unable to see latest log files/data in splunk 3. What to do if log files are missing in splunk forwarder after patching, how to add files or what is the correct approach
... View more