We have just discovered that we have lost a large amount of data. Does Splunk log when it deletes buckets? I found [this question](https://answers.splunk.com/answers/368068/how-do-i-see-whatif-buckets-were-deleted-by-splunk.html) that references SPLUNK_HOME/var/log/splunk/splunkd_stdout.log, but I do not see that file on v7.0.2.
Is this something I have to turn on? Was it moved? Is there a better way?
↧