I have a user that is reporting that data is dropping out from a large search in splunk after a time. The user reported that the counter for IPcount was resetting for the most common event after time and restarted counting.
What should I be looking at to override when splunk drops out results.
Here is the query they were using...
sourcetype=web_access source=access | rex field=_raw "(?
I guess it's better to create summary index first to make your data smaller (summarize your data a bit) and search it again.
collect index = [summary]