Hi Surekha , this is how we fixed the issue : "we had to edit "change_request.sys_updated_on" in the location "%SplunkHome%\var\lib\splunk\modinputs" and change the date to the one from where we were missing the Change data through search query i.e from 08/25/2016, as it was holding the future date i.e 2017-09-03, files were not getting indexed.
The issue was caused when SNOW team had installed a plugin that generated bogus Change tickets with future time stamps... Also you can see the ta_snow logs for any other errors and let us know if this does not work.
... View more