<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog data missing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15520#M1751</link>
    <description>&lt;P&gt;I encountered a similar scenario.  The above error message was found in splunkd.log.  I then learned Splunk was sometimes being started as 'splunkuser' and other times as 'root'.  'root' could access UDP 514, 'splunkuser' could not.  I re-directed syslog to a file and monitored file for resolution.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jun 2010 21:25:24 GMT</pubDate>
    <dc:creator>bwooden</dc:creator>
    <dc:date>2010-06-18T21:25:24Z</dc:date>
    <item>
      <title>syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15515#M1746</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;

&lt;P&gt;Im trying to troubleshoot an issue where syslog data seems to stop for a couple of days, then pick up again. All on its own.&lt;/P&gt;

&lt;P&gt;I have checked metrics.log and there is data coming in.&lt;BR /&gt;
I have run many searches and have found that the data comes in steadily, and almost constantly.&lt;BR /&gt;
I have checked that the indexed time is the same as the timestamp splunk gives the events.&lt;BR /&gt;
What else? - I have checked splunkd.log and made sure that there was no data being blocked, i have done the same on metrics.log&lt;/P&gt;

&lt;P&gt;I also have splunked their diag and can confirm that there is no data deletion going on here.
The indexes.conf and inputs.conf do not show anything fishy as well.
I have also checked to see if there is any data going to the null queue, but see none.&lt;/P&gt;

&lt;P&gt;I am in the process of doing some bucket analysis but am awaiting more data from the customer.
Any ideas on what else i can look for?&lt;BR /&gt;
Thanks in advance,&lt;BR /&gt;
.gz&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2010 07:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15515#M1746</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-06-15T07:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15516#M1747</link>
      <description>&lt;P&gt;I suppose my question is, what reason to have to believe that the data ever stops, if metrics show it coming in and searches show continuous data, &lt;EM&gt;and&lt;/EM&gt; you know nothing has been deleted? Where are you &lt;EM&gt;not&lt;/EM&gt; seeing data that you would expect? Also, I have seen a pure auto-timestamping decide that the &lt;EM&gt;year&lt;/EM&gt; of the data is a different year (since syslog doesn't have a year in the timestamp).&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2010 08:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15516#M1747</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-06-15T08:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15517#M1748</link>
      <description>&lt;P&gt;to confirm that data is not in the system i do a source="udp*"&lt;BR /&gt;
to confirm that data keeps coming in i check the metrics.log as well as search index=_internal source=metrics.log and see that there are events coming in at a steady, almost constant rate.&lt;BR /&gt;
Lastly, as i mentioned, when i do a search on the last one, i add _indextime to the fields and see that it is the same as the timestamp that splunk indexes that event (note, here i am talking about index=_internal source="udp*")&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15517#M1748</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2020-09-28T09:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15518#M1749</link>
      <description>&lt;P&gt;I would peak at the data coming in with tcpdump or snoop or wireshark just to really see it is what it is expected to be.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2010 20:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15518#M1749</guid>
      <dc:creator>rotten</dc:creator>
      <dc:date>2010-06-15T20:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15519#M1750</link>
      <description>&lt;P&gt;Do you see any "Error binding to socket in UDPInputProcessor: Permission Denied" in splunkd.log?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2010 00:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15519#M1750</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2010-06-18T00:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15520#M1751</link>
      <description>&lt;P&gt;I encountered a similar scenario.  The above error message was found in splunkd.log.  I then learned Splunk was sometimes being started as 'splunkuser' and other times as 'root'.  'root' could access UDP 514, 'splunkuser' could not.  I re-directed syslog to a file and monitored file for resolution.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2010 21:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15520#M1751</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2010-06-18T21:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: syslog data missing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15521#M1752</link>
      <description>&lt;P&gt;Issue seems to have been fixed.
Not sure if the update to recent version is what fixed it or if they are just better connected to the syslog server.. 
In anycase, customer seems to be content!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2010 03:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-data-missing/m-p/15521#M1752</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-14T03:45:19Z</dc:date>
    </item>
  </channel>
</rss>

