<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How did logs from a heavy forwarder get indexed when Splunk was not running? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273329#M52458</link>
    <description>&lt;P&gt;Open the events of the log and check if are there events from 23:00&lt;/P&gt;

&lt;P&gt;Hope i help you&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2016 09:43:40 GMT</pubDate>
    <dc:creator>jmallorquin</dc:creator>
    <dc:date>2016-04-04T09:43:40Z</dc:date>
    <item>
      <title>How did logs from a heavy forwarder get indexed when Splunk was not running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273326#M52455</link>
      <description>&lt;P&gt;Splunk was running on a heavy forwarder during the time period 00:00 to 00:20. Related logs also have been found in splunkd.log &amp;amp; splunkd_stderr.log.&lt;BR /&gt;
I got few logs from the HF at 23:00. How is it possible?&lt;BR /&gt;
If Splunk is not running, how did these logs get indexed?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 05:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273326#M52455</guid>
      <dc:creator>Madhan45</dc:creator>
      <dc:date>2016-04-04T05:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: How did logs from a heavy forwarder get indexed when Splunk was not running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273327#M52456</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;If the logs has timestamp, splunk index in the timestamp of the log. So if the log was create at 23:00, its normal that you have events in that time. Also review the timezone in which you are index the events.&lt;/P&gt;

&lt;P&gt;Hope i help you.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 09:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273327#M52456</guid>
      <dc:creator>jmallorquin</dc:creator>
      <dc:date>2016-04-04T09:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: How did logs from a heavy forwarder get indexed when Splunk was not running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273328#M52457</link>
      <description>&lt;P&gt;The event generated time and index time both are same. there was no lagging in event. splunk was running only for the time period 00:00 00:20 after thet till now i didn't start splunk. then how did those logs get index?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 09:41:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273328#M52457</guid>
      <dc:creator>Madhan45</dc:creator>
      <dc:date>2016-04-04T09:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: How did logs from a heavy forwarder get indexed when Splunk was not running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273329#M52458</link>
      <description>&lt;P&gt;Open the events of the log and check if are there events from 23:00&lt;/P&gt;

&lt;P&gt;Hope i help you&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 09:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-did-logs-from-a-heavy-forwarder-get-indexed-when-Splunk-was/m-p/273329#M52458</guid>
      <dc:creator>jmallorquin</dc:creator>
      <dc:date>2016-04-04T09:43:40Z</dc:date>
    </item>
  </channel>
</rss>

