I am trying to troubleshoot disappearing logs. Logs that are associated with a particular data stream have disappeared (I am not able to find under the data stream) outside of office hours. As they have disappeared in the middle of the night, no changes from our side have been done to elastic. The only clue I have is that the data stream have been updated in the time logs disappeared. Health of data stream is green.
How I can see more information for this updated (I can see Last updated date in the data Streams bot nothing more)? If not I was thinking of rollover the stream but not sure if this is going to make any difference.
Sorry, probably my explanation was misleading (as I am new to elastic). By disappearing I meant - no new logs have appeared under this data stream (I have checked logs are sent). Old logs can still be seen under Analytics/Discover.
Yes, there is a ILM policy but it haven't been touched when the logs stopped appearing.
Is there a way to see what have been updated into the data stream?