Could the issue be related to bucket settings (Hot>Warm>Cold>Frozen)
I last ran search @ 1700 last night host=Linuxhostname - returned the 6.2 and 6.3 (24 hours) results (Modifiers were for last 30 days)
I Ran same search @ 0600 It returned 6.3 and 6.4 (Time modifiers set for 30 days)
Could the issue be bucket freeze?
I ran index=_internal sourcetype=splunkd component=BucketMover
and saw 27 moves to cold or freeze--- mostly freeze
Based on the fact that until yesterday- Linux hosts were overrunning indexer with 10,000,000 inputs per 8 hours This was due to Issues with the Linux UNIX addon , which has now been disabled.
/
Question is thawing buckets en-masse advisable?
I have been googling-- but want to not use a "poke and hope" method to thaw.
I have seen different methods- including this.
https://splunkonbigdata.com/2019/02/27/retrieving-data-from-archive-state/
Thoughts please
... View more