Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Indexed data vanishes after few hours and cause 0 events for 2 3 hours time frame in a day

$
0
0
I have a Clustered environment and monitoring setup for application logs,universal forwarders push data to indexers . Lately , I have been facing issue where the application logs are getting indexed and available . But after few hours when I search for the present day logs on splunk there are 0 events for 2 3 hours time frame and indexed data vanishes. Not sure if this is a known issue , any help would be of much help. Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>