When events are not being parsed correctly, the _internal index holds the clues. Parsing warnings about line-breaking, timestamp extraction failures, and truncated events all show up there.
Common issues include events being merged together (SHOULD_LINEMERGE too aggressive) or timestamps not being extracted (wrong TIME_FORMAT in props.conf).