<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk heavy forwarder data forwarding issue.  WARN  DateParserVerbose - The same timestamp has been used for 1000K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473211#M24363</link>
    <description>&lt;P&gt;are the events really have the same timestamp?&lt;BR /&gt;
see nice elaborated answer here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/303/whats-max-events-i-can-have-timestamped-with-a-particular-second-millisecond.html"&gt;https://answers.splunk.com/answers/303/whats-max-events-i-can-have-timestamped-with-a-particular-second-millisecond.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Nov 2019 03:13:01 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2019-11-01T03:13:01Z</dc:date>
    <item>
      <title>Splunk heavy forwarder data forwarding issue.  WARN  DateParserVerbose - The same timestamp has been used for 1000K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473210#M24362</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm facing issue with data forwarding to splunk. i'm not sure where data being dropped and its happening randomly.&lt;BR /&gt;
Details:&lt;BR /&gt;
I have text (key-value pair) file with 6.5 million lines(events) with same timestamp (_time) configured. &lt;BR /&gt;
but while ingesting file to splunk via Heavy forwarder, it automatically incrementing _time +1 sec for every 100k or 200k events  randomly.&lt;BR /&gt;
Observation:&lt;BR /&gt;
if the _time +1 sec  increment happens  for every 100k events, then no issues data completely ingest to splunk.&lt;BR /&gt;
if some times _time +1 sec increment happens for 200+k events, we are observing data drop, only 4 to 4.5 million events got ingested out of 6.5 million events.&lt;/P&gt;

&lt;P&gt;splunk log giving this warning:&lt;BR /&gt;
WARN  DateParserVerbose - The same timestamp has been used for 500K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable&lt;/P&gt;

&lt;P&gt;Splunk Environment details:&lt;BR /&gt;
Splunk Version: 7.2.6&lt;BR /&gt;
OS: AWS Linux Machine&lt;/P&gt;

&lt;P&gt;Could you please advice what is root cause of this issue and remedy for same.&lt;/P&gt;

&lt;P&gt;Thanks In Advance !!!.&lt;BR /&gt;
Mani&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 02:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473210#M24362</guid>
      <dc:creator>manikandankasi</dc:creator>
      <dc:date>2019-11-01T02:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarder data forwarding issue.  WARN  DateParserVerbose - The same timestamp has been used for 1000K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473211#M24363</link>
      <description>&lt;P&gt;are the events really have the same timestamp?&lt;BR /&gt;
see nice elaborated answer here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/303/whats-max-events-i-can-have-timestamped-with-a-particular-second-millisecond.html"&gt;https://answers.splunk.com/answers/303/whats-max-events-i-can-have-timestamped-with-a-particular-second-millisecond.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 03:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473211#M24363</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-11-01T03:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarder data forwarding issue.  WARN  DateParserVerbose - The same timestamp has been used for 1000K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473212#M24364</link>
      <description>&lt;P&gt;Thanks Adonio for reply..&lt;BR /&gt;
yes all 6.5 million event has same timestamp.&lt;BR /&gt;
My concern is the data drop happening randomly. not consistence. how some times increment +1 sec for every 100k events and some time 200+k events.&lt;BR /&gt;
Does Splunk version 7.2.6 has the capability to handle this scenario?&lt;BR /&gt;
Could you please advise any work around for same. is there any limits needs to updated to handle this?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Mani&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 03:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473212#M24364</guid>
      <dc:creator>manikandankasi</dc:creator>
      <dc:date>2019-11-01T03:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarder data forwarding issue.  WARN  DateParserVerbose - The same timestamp has been used for 1000K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473213#M24365</link>
      <description>&lt;P&gt;you can add the index time timestamp to each event&lt;BR /&gt;
in &lt;CODE&gt;props.conf&lt;/CODE&gt; under the relevant sourcetype stanza, add:&lt;BR /&gt;
&lt;CODE&gt;DATETIME_CONFIG = CURRENT&lt;/CODE&gt;&lt;BR /&gt;
read here more:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/admin/Propsconf"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 12:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-heavy-forwarder-data-forwarding-issue-WARN/m-p/473213#M24365</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-11-01T12:09:38Z</dc:date>
    </item>
  </channel>
</rss>

