<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs by udp syslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293466#M55834</link>
    <description>&lt;P&gt;There an upgrade on my problem:&lt;BR /&gt;
I found that events are indexed but with a wrong year date Nov 22 2016 !&lt;BR /&gt;
This is the indexed log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Nov 22 16:35:23 xx.xx.xx.xx Nov 22 16:35:31 CRM-ACS-A1 CSCOacs_Failed_Attempts 0000991147 2 0 2017-11-22 16:35:31.951 +01:00 ....
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But the problem is now: why Splunk read a wrong year?&lt;BR /&gt;
Year isn't declared in logs but both Indexers and HFs system date are correct (2017).&lt;/P&gt;

&lt;P&gt;Anyone has an idea where search the problem?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2017 15:45:21 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-11-22T15:45:21Z</dc:date>
    <item>
      <title>logs by udp syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293465#M55833</link>
      <description>&lt;P&gt;HI at all I have a very strange thing:&lt;BR /&gt;
I'm using Splunk 7.0.0 in all systems.&lt;BR /&gt;
I have two Heavy Forwarders with a Load Balancer Netscaler in front of, that receive syslogs and send them to two Indexers.&lt;BR /&gt;
There a Cisco ACS that sends syslogs to my HFs and it was running.&lt;/P&gt;

&lt;P&gt;Some time ago there was an upgrade of Cisco ACS so from that moment I don't receive more events.&lt;BR /&gt;
Checking Splunk logs I found that I have in _internal from the HFs the following logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;11-22-2017 15:24:14.423 +0100 INFO  Metrics - group=udpin_connections, xx.xx.xx.xx:514, sourcePort=514, _udp_bps=71.82, _udp_kbps=0.07, _udp_avg_thruput=0.08, _udp_kprocessed=27.53, _udp_eps=0.10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;11-22-2017 15:24:14.420 +0100 INFO  Metrics - group=per_host_thruput, series="xx.xx.xx.xx", kbps=0.0650822688668127, eps=0.06451524038685016, kb=2.017578125, ev=2, avg_age=31536011.5, max_age=31536023
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Where xx.xx.xx.xx is the HFs IP address.&lt;BR /&gt;
And this means that HFs are receiving logs, but they aren't indexed.&lt;/P&gt;

&lt;P&gt;Anyone can help me to understand what's happening?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293465#M55833</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-22T14:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: logs by udp syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293466#M55834</link>
      <description>&lt;P&gt;There an upgrade on my problem:&lt;BR /&gt;
I found that events are indexed but with a wrong year date Nov 22 2016 !&lt;BR /&gt;
This is the indexed log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Nov 22 16:35:23 xx.xx.xx.xx Nov 22 16:35:31 CRM-ACS-A1 CSCOacs_Failed_Attempts 0000991147 2 0 2017-11-22 16:35:31.951 +01:00 ....
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But the problem is now: why Splunk read a wrong year?&lt;BR /&gt;
Year isn't declared in logs but both Indexers and HFs system date are correct (2017).&lt;/P&gt;

&lt;P&gt;Anyone has an idea where search the problem?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 15:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293466#M55834</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-22T15:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: logs by udp syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293467#M55835</link>
      <description>&lt;P&gt;I found the problem: I don't know why Splunk didn't use the first timestamp in stead used the second interpreting last number of IP address as year, so timestamp was the highlighted&lt;/P&gt;

&lt;P&gt;Nov 22 16:35:23 xx.xx.xx.&lt;STRONG&gt;16 Nov 22 16:35:31&lt;/STRONG&gt; CRM-ACS-A1 CSCOacs_Failed_Attempts 0000991147 2 0 2017-11-22 16:35:31.951 +01:00 ....&lt;/P&gt;

&lt;P&gt;and event was indexed with timestamp&lt;BR /&gt;
2016-11-22 16:53:31&lt;/P&gt;

&lt;P&gt;This could be useful for others.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-by-udp-syslog/m-p/293467#M55835</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T16:56:22Z</dc:date>
    </item>
  </channel>
</rss>

