<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why did we experience a Log drop from Gsuite? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591326#M103573</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;
&lt;P&gt;We are streaming google app logs to splunk in distributed environment. We have G suite for Splunk app on SH and Input add-on on Heavy forwarder. I am seeing log drop on a particular day for about 2 hrs and then the logging has turned normal. Unable to identify the reason for the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akasmika_0-1648579964460.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18820iB773D3050273E14F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akasmika_0-1648579964460.png" alt="akasmika_0-1648579964460.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also the g suite application health dashboard shows the below error,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akasmika_1-1648580100762.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18821i8D108D49E8C3065A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akasmika_1-1648580100762.png" alt="akasmika_1-1648580100762.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3514"&gt;@alacercogitatus&lt;/a&gt;&amp;nbsp;, could you please help me identify the cause for logs drop and how to fix these errors?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 20:11:02 GMT</pubDate>
    <dc:creator>akasmika</dc:creator>
    <dc:date>2022-03-29T20:11:02Z</dc:date>
    <item>
      <title>Why did we experience a Log drop from Gsuite?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591326#M103573</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;
&lt;P&gt;We are streaming google app logs to splunk in distributed environment. We have G suite for Splunk app on SH and Input add-on on Heavy forwarder. I am seeing log drop on a particular day for about 2 hrs and then the logging has turned normal. Unable to identify the reason for the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akasmika_0-1648579964460.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18820iB773D3050273E14F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akasmika_0-1648579964460.png" alt="akasmika_0-1648579964460.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also the g suite application health dashboard shows the below error,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akasmika_1-1648580100762.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18821i8D108D49E8C3065A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akasmika_1-1648580100762.png" alt="akasmika_1-1648580100762.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3514"&gt;@alacercogitatus&lt;/a&gt;&amp;nbsp;, could you please help me identify the cause for logs drop and how to fix these errors?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 20:11:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591326#M103573</guid>
      <dc:creator>akasmika</dc:creator>
      <dc:date>2022-03-29T20:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log drop from Gsuite</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591327#M103574</link>
      <description>&lt;P&gt;I'd need app name and version. "G Suite" is not supported. "Google Workspace" is. You can also shoot me an email at the listed &lt;A href="https://splunkbase.splunk.com/app/5498/" target="_blank"&gt;https://splunkbase.splunk.com/app/5498/&lt;/A&gt; and we can triage there. But I need the app and version first to correlate that line number. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 19:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591327#M103574</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2022-03-29T19:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log drop from Gsuite</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591334#M103575</link>
      <description>&lt;P&gt;App and Version on SH:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3791/" target="_blank"&gt;https://splunkbase.splunk.com/app/3791/&lt;/A&gt;&amp;nbsp;(1.4.2)&lt;/P&gt;&lt;P&gt;Input add-on on HF and version:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3793/" target="_blank"&gt;https://splunkbase.splunk.com/app/3793/&lt;/A&gt;&amp;nbsp;(1.4.2)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 19:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591334#M103575</guid>
      <dc:creator>akasmika</dc:creator>
      <dc:date>2022-03-29T19:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Log drop from Gsuite</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591347#M103576</link>
      <description>&lt;P&gt;Those aren't supported due to Python2 and "old sdk" from google. Please upgrade and see if you still get that drop. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 20:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591347#M103576</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2022-03-29T20:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log drop from Gsuite</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591355#M103578</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3514"&gt;@alacercogitatus&lt;/a&gt;&amp;nbsp;, the app or add-on version we have is the latest one I can see on splunk base(1.4.2) What surprises me is the logs have not stop completely but only for sometime. How can python or old sdk be the cause while it is working partially.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 20:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-we-experience-a-Log-drop-from-Gsuite/m-p/591355#M103578</guid>
      <dc:creator>akasmika</dc:creator>
      <dc:date>2022-03-29T20:55:15Z</dc:date>
    </item>
  </channel>
</rss>

