Splunk Search

I am not able to find a few lines of my data in Splunk

varun99
Path Finder

If I see the file on the server, it has the data. But in splunk, I am able to see all the data except for a few lines. Kindly let me know why it could be happening and what can I do to resolve this kind of behavior.

I am using a simple query like source="filePATH"

0 Karma

obrosch
Path Finder

Do you see your events when you switch to verbose mode and use the raw mode in the events section? Then it is a problem with the line breaking. Maybe you have a regex which filters these events out. This you can find in the props / transforms file.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm betting the line breaking is not working as expected and your searching on data that is present in one event but not the split part. Are you able to narrow your search down for exactly what your looking for rather than just specifying source?

0 Karma

pradeepkumarg
Influencer

Does the missing events differ in any way? Particularly the time stamp on them? Does your TIME FORMAT specification on props.conf for the source type extract correctly for the missing events?

If TIME FORMAT is the issue, you will be able to find the events by searching for a larger time range. Try a few years before and after.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...