Splunk Search

How do I edit my timechart search to show all requested data?

OldManEd
Builder

I am running the following search:

index=_internal source=*metrics.log 
earliest=07/01/2015:00:00:0 
latest=08/10/2015:23:59:59 
| eval GB=kb/(1024*1024) 
| search group="per_index_thruput" 
| timechart span=1d sum(GB) by series limit=15

But when I run it, the chart data only goes back to July 13th.

alt text

Is there any way I can change the search to display all the data?

~Ed

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

The default retention period of the _internal index is 30 days (in indexes.conf on Indexers, frozenTimePeriodInSecs = 2592000). That's why the data that you see is approximately 30 days old. (there is no data to show beyond that point)

View solution in original post

somesoni2
Revered Legend

The default retention period of the _internal index is 30 days (in indexes.conf on Indexers, frozenTimePeriodInSecs = 2592000). That's why the data that you see is approximately 30 days old. (there is no data to show beyond that point)

OldManEd
Builder

Oh heck. thanks for the info.
~Ed

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...