<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log latency in Security</title>
    <link>https://community.splunk.com/t5/Security/Log-latency/m-p/697130#M18089</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We could see latency in logs&lt;BR /&gt;&lt;BR /&gt;Log ingestion via - syslog&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Network devices --&amp;gt; Syslog server --&amp;gt; splunk&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Using below query, we could see minimum 10 mins to maxminum 60 mins log latency&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="ABC" sourcetype="syslog" source="/syslog*" 
| eval indextime=strftime(_indextime,"%c")
| table _raw _time indextime&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;What should be our next steps to check where the latency is and how to fix it?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 11:00:13 GMT</pubDate>
    <dc:creator>VijaySrrie</dc:creator>
    <dc:date>2024-08-23T11:00:13Z</dc:date>
    <item>
      <title>Log latency</title>
      <link>https://community.splunk.com/t5/Security/Log-latency/m-p/697130#M18089</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We could see latency in logs&lt;BR /&gt;&lt;BR /&gt;Log ingestion via - syslog&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Network devices --&amp;gt; Syslog server --&amp;gt; splunk&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Using below query, we could see minimum 10 mins to maxminum 60 mins log latency&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="ABC" sourcetype="syslog" source="/syslog*" 
| eval indextime=strftime(_indextime,"%c")
| table _raw _time indextime&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;What should be our next steps to check where the latency is and how to fix it?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 11:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-latency/m-p/697130#M18089</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2024-08-23T11:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Log latency</title>
      <link>https://community.splunk.com/t5/Security/Log-latency/m-p/697249#M18091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/164779"&gt;@VijaySrrie&lt;/a&gt;&amp;nbsp;assuming you are collecting the logs on syslog server then forwarding to Splunk with a UF?&lt;BR /&gt;You can check if the UF is reaching its thruput limit which could cause indexing lag:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd component=ThruputProcessor "has reached maxKBps" &lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 05:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-latency/m-p/697249#M18091</guid>
      <dc:creator>KendallW</dc:creator>
      <dc:date>2024-08-26T05:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Log latency</title>
      <link>https://community.splunk.com/t5/Security/Log-latency/m-p/697562#M18093</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121137"&gt;@KendallW&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;ThruputProcessor&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;2963&lt;/SPAN&gt; &lt;SPAN class=""&gt;parsing&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;data&lt;/SPAN&gt; &lt;SPAN class=""&gt;throughput&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;5125&lt;/SPAN&gt; &lt;SPAN class=""&gt;kb/s&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;reached&lt;/SPAN&gt; &lt;SPAN class=""&gt;maxKBps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN class=""&gt;As&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;result&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;data&lt;/SPAN&gt; &lt;SPAN class=""&gt;forwarding&lt;/SPAN&gt; &lt;SPAN class=""&gt;may&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt; &lt;SPAN class=""&gt;throttled.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Consider&lt;/SPAN&gt; &lt;SPAN class=""&gt;increasing&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;value&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;maxKBps&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;limits.conf.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;We will try increasing the limits.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 08:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-latency/m-p/697562#M18093</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2024-08-28T08:53:24Z</dc:date>
    </item>
  </channel>
</rss>

