Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Losing data when time frame is 30+ days

$
0
0
If I'm looking at Last 30 Days of data for one event and doing a timechart, a couple of days come up with 0s as results. When I adjust my timeframe to look at those days (and surrounding days) to see what might be going on, everything looks completely normal and I have about the same number of events and the same averages/sums in my timechart as the other days surrounding it. I'm curious why a larger timeframe might be losing data. It isn't a complex search. There are no joins, just one sourcetype with a few qualifiers and then the timechart. I've also tried to do a stats by date, but that didn't work either.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>