Splunk Dev

Splunk Indexed Data Mysteriously Disappears

johnboldt
Explorer

We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...