<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Will&amp;quot; _internal&amp;quot; index records the error that occur during integration in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613821#M13966</link>
    <description>&lt;P&gt;No, the _internal index does not collect data from endpoints (except for UFs).&amp;nbsp; It logs Splunk's own event messages, including those from search heads, indexers, and forwarders.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the query I provided was very basic - as was the question it answered.&amp;nbsp; For more specific help, ask a more specific question.&amp;nbsp; Experiment with it until you end up with a query (or several) that suits your use case(s).&lt;/P&gt;&lt;P&gt;Components are useful to filter on.&amp;nbsp; There are many, perhaps hundreds, of components, so I can't document them here (not sure they're documented anywhere), but some of the more useful ones for finding onboarding issues are:&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;LineBreakingProcessor&lt;/STRONG&gt;,&amp;nbsp;&lt;STRONG&gt;Metrics&lt;/STRONG&gt; (shows throughput, among other things),&amp;nbsp;&lt;STRONG&gt;HttpListener&lt;/STRONG&gt; (if using HEC),&amp;nbsp;&lt;STRONG&gt;TailReader&lt;/STRONG&gt; (tells about monitored files),&amp;nbsp;&lt;STRONG&gt;TcpInputProc&lt;/STRONG&gt; (connections from other Splunk instances),&amp;nbsp;&lt;STRONG&gt;DateParserVerbose&lt;/STRONG&gt; (timestamp parsing errors),&amp;nbsp;&lt;STRONG&gt;Aggregator*&lt;/STRONG&gt; (line merging issues).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2022 18:59:41 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-09-20T18:59:41Z</dc:date>
    <item>
      <title>When an error occurs during integration process, will that be recorded by "_internal" index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613784#M13961</link>
      <description>&lt;P&gt;Hey Splunkers !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When an error occur during integration process, will that be recorded by "_internal" index??&lt;/P&gt;
&lt;P&gt;Will data on-boarding / data parsing errors recorded by the _internal index....?&lt;/P&gt;
&lt;P&gt;if so , logical SPL query to trouble shoot those errors would be welcome&lt;/P&gt;
&lt;P&gt;what kind of integration errors will be recorded in _internal index ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 18:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613784#M13961</guid>
      <dc:creator>restinlinux</dc:creator>
      <dc:date>2022-09-20T18:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Will" _internal" index records the error that occur during integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613808#M13963</link>
      <description>&lt;P&gt;It depends on the type of integration and how it is done, but, yes, there often is something in _internal when a problem occurs during data onboarding.&lt;/P&gt;&lt;P&gt;Some common error messages pertain to timestamp parsing, line breaking, scripted input failure, and much more.&lt;/P&gt;&lt;P&gt;The exact SPL query will depend on what you seek, but start with &lt;FONT face="courier new,courier"&gt;index=_internal error&lt;/FONT&gt; and go from there.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 16:40:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613808#M13963</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-09-20T16:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Will" _internal" index records the error that occur during integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613814#M13964</link>
      <description>&lt;P&gt;Thanks !&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it collects network relative issues from the endpoints ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;And will errors that occur during forwarding data will be recorded on _internal index&lt;/P&gt;&lt;P&gt;The query is really a basic which bring up all the error events in the _internal index...&lt;/P&gt;&lt;P&gt;Looking and working on some nice SQL like to calculate all the errors based on its type (parsing , Time Stamp,etc..) during the integration&lt;/P&gt;&lt;P&gt;And&amp;nbsp; by analyzing the _internal index , there's a field named component with lot values which seems to be interesting .. if possible can you brief this field values.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;RestinLinux&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 18:01:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613814#M13964</guid>
      <dc:creator>restinlinux</dc:creator>
      <dc:date>2022-09-20T18:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Will" _internal" index records the error that occur during integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613821#M13966</link>
      <description>&lt;P&gt;No, the _internal index does not collect data from endpoints (except for UFs).&amp;nbsp; It logs Splunk's own event messages, including those from search heads, indexers, and forwarders.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the query I provided was very basic - as was the question it answered.&amp;nbsp; For more specific help, ask a more specific question.&amp;nbsp; Experiment with it until you end up with a query (or several) that suits your use case(s).&lt;/P&gt;&lt;P&gt;Components are useful to filter on.&amp;nbsp; There are many, perhaps hundreds, of components, so I can't document them here (not sure they're documented anywhere), but some of the more useful ones for finding onboarding issues are:&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;LineBreakingProcessor&lt;/STRONG&gt;,&amp;nbsp;&lt;STRONG&gt;Metrics&lt;/STRONG&gt; (shows throughput, among other things),&amp;nbsp;&lt;STRONG&gt;HttpListener&lt;/STRONG&gt; (if using HEC),&amp;nbsp;&lt;STRONG&gt;TailReader&lt;/STRONG&gt; (tells about monitored files),&amp;nbsp;&lt;STRONG&gt;TcpInputProc&lt;/STRONG&gt; (connections from other Splunk instances),&amp;nbsp;&lt;STRONG&gt;DateParserVerbose&lt;/STRONG&gt; (timestamp parsing errors),&amp;nbsp;&lt;STRONG&gt;Aggregator*&lt;/STRONG&gt; (line merging issues).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 18:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613821#M13966</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-09-20T18:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Will" _internal" index records the error that occur during integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613897#M13974</link>
      <description>&lt;P&gt;The easiest way to look those which&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;pointed out is MC. Just open it and look Indexing -&amp;gt; Inputs -&amp;gt; Data Quality. Then select suitable Time Range and other offered filters and you will get list off issues. You could drill down with those values to look more detailed level of those issues.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 08:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-an-error-occurs-during-integration-process-will-that-be/m-p/613897#M13974</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-21T08:57:39Z</dc:date>
    </item>
  </channel>
</rss>

