<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256486#M49288</link>
    <description>&lt;P&gt;Can you post a few log samples? Have you tried searching for a known missing log over all time? In the future? (&lt;CODE&gt;earliest=now latest=+1mon&lt;/CODE&gt;)&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2016 21:44:46 GMT</pubDate>
    <dc:creator>twinspop</dc:creator>
    <dc:date>2016-07-14T21:44:46Z</dc:date>
    <item>
      <title>How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256481#M49283</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have an issue with Splunk getting data into indexes. We are getting data only during one hour (12.00 AM to 12.59 AM) every day. We have not specified any interval though in inputs.conf.&lt;/P&gt;

&lt;P&gt;Can you please advise why it is restricting indexing to this one hour?&lt;/P&gt;

&lt;P&gt;Please note that we have data in log files, verified our Universal forwarders side.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 19:18:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256481#M49283</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-07-14T19:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256482#M49284</link>
      <description>&lt;P&gt;Could you post your inputs.conf configuration? Do you see on Data Summary the data is being indexed?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 19:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256482#M49284</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2016-07-14T19:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256483#M49285</link>
      <description>&lt;P&gt;Hi Below is in inputs.conf.&lt;/P&gt;

&lt;P&gt;[monitor:///inpu/server*/logs/ca/data/]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
sourcetype = app:fp__ca&lt;BR /&gt;
index = imdc_a&lt;/P&gt;

&lt;P&gt;yes, we could see in datasummary  the data is available from 12.00 AM to 12.59 AM.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Sarath&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256483#M49285</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2020-09-29T10:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256484#M49286</link>
      <description>&lt;P&gt;Do you see any messages on splunkd.log?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 19:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256484#M49286</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2016-07-14T19:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256485#M49287</link>
      <description>&lt;P&gt;No, we don't see any errors or message &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 20:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256485#M49287</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-07-14T20:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256486#M49288</link>
      <description>&lt;P&gt;Can you post a few log samples? Have you tried searching for a known missing log over all time? In the future? (&lt;CODE&gt;earliest=now latest=+1mon&lt;/CODE&gt;)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 21:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256486#M49288</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2016-07-14T21:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256487#M49289</link>
      <description>&lt;P&gt;Below are sample logs &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-14-2016 00:00:09.430 -0700 INFO  ClientSessionsManager:Listener_AppEvents - Received count=3 AppEvents 
07-14-2016 00:00:09.702 -0700 INFO  PubSubSvr - Subscribed: channel=tenantService/handshake/reply/sgplu803/164E6DE8-9406-48ED-87D3-72BE00EFCC3E
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 15 Jul 2016 00:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256487#M49289</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-07-15T00:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256488#M49290</link>
      <description>&lt;P&gt;Can you see the index time?&lt;BR /&gt;
・・・| eval indextime=strftime(_indextime,"%Y/%m/%d %H:%M:%S")|table _time indextime&lt;/P&gt;

&lt;P&gt;Or format of this log can be confirmed?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 00:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256488#M49290</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2016-07-15T00:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256489#M49291</link>
      <description>&lt;P&gt;Hello splunker9999, have you confirmed there are logs on the instance with timestamps outside of (12.00 AM to 12.59 AM) ? &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 01:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256489#M49291</guid>
      <dc:creator>phadnett_splunk</dc:creator>
      <dc:date>2016-07-15T01:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256490#M49292</link>
      <description>&lt;P&gt;Yes confirm, Today also we got event from 12.00 to 12.59 AM&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256490#M49292</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-07-15T17:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256491#M49293</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;_time and Index time for my data: Indexing is stopped exactly around 1.00 AM 

50 Per Page Format  Preview Prev 1 2 3 4 5 6 7 8 9 ... Next
_time                                    indextime
2016-07-15 00:59:59.665 2016/07/15 01:00:00
2016-07-15 00:59:59.665 2016/07/15 01:00:00
2016-07-15 00:59:54.652 2016/07/15 00:59:55
2016-07-15 00:59:54.652 2016/07/15 00:59:55
2016-07-15 00:59:49.642 2016/07/15 00:59:50
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256491#M49293</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-07-15T17:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256492#M49294</link>
      <description>&lt;P&gt;Hello Splunk9999, sorry for the confusion, I meant the actual log file you are monitoring. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-data-is-only-getting-indexed-in-Splunk/m-p/256492#M49294</guid>
      <dc:creator>phadnett_splunk</dc:creator>
      <dc:date>2016-07-15T17:12:13Z</dc:date>
    </item>
  </channel>
</rss>

