Splunk Dev

Splunk Indexed Data Mysteriously Disappears

johnboldt
Explorer

We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in our index timeline. I did a search on the _internal index for the "delete" keyword and I'm not seeing any delete commands issued. I'm not seeing anything in the _audit index either. So I have two questions: why is this happening, and how do I fill in the gaps where data is missing?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Seems extremely unlikely, unless it happens that you are hitting limits on your index size, and it is simply being naturally rolled out to accommodate newer data.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...