Splunk Search

What happened to the data?

SumanPalisetty
Path Finder

Hi,

I have a question for my understanding. Kindly help.

You had data in the past, one fine day if you see there is no data, how do you troubleshoot?

Regards

Suman P.

Labels (1)
Tags (2)
0 Karma
1 Solution

FrankVl
Ultra Champion

This page in Splunk Docs is a good starting point:

https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata

In the end in boils down to understanding how exactly that data is supposed to come into splunk and then in a structured way troubleshoot which of the components in the chain that handles that data ingest is broken. The exact steps will differ depending on the ingest mechanism.

View solution in original post

FrankVl
Ultra Champion

This page in Splunk Docs is a good starting point:

https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata

In the end in boils down to understanding how exactly that data is supposed to come into splunk and then in a structured way troubleshoot which of the components in the chain that handles that data ingest is broken. The exact steps will differ depending on the ingest mechanism.

SumanPalisetty
Path Finder

Hi,

Please give the answer in  couple of lines for both the scenarios. For

1. Data from a certain date or certain sourcetype or index is missing

2. All the data is missing

Regards

Suman P.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Check retention periods for your indexes if data past a certain date is missing

Try loosening the filters on your searches to see if the data appears

Check the status of the indexes (how much data do they have in them)

ITWhisperer
SplunkTrust
SplunkTrust

You are going to have to be more specific - is it that all of your data is "missing" or only prior to a particular point in time? Is it that some data is found by some searches but not by others? Can you narrow down the circumstances which lead to the missing data?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...