<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I index data in real time? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345649#M63498</link>
    <description>&lt;P&gt;Hi @chintan_shah,&lt;/P&gt;

&lt;P&gt;Are you getting any error in Splunk Universal Forwarder's splunkd.log ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harshil&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2017 15:30:57 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2017-09-27T15:30:57Z</dc:date>
    <item>
      <title>How can I index data in real time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345648#M63497</link>
      <description>&lt;P&gt;I have created an alert which checks if logs are not present in last 20 mins per source. I have around 32 source files from single forwarder. Many of my files are not getting indexed in real time and I am receiving this alert frequently.&lt;/P&gt;

&lt;P&gt;Can anyone tell me any parameters which needs to be changed so that I can index the data in real time?&lt;BR /&gt;
is there any mechanism to check what is the inflow rate of the data?&lt;/P&gt;

&lt;P&gt;System Info:&lt;BR /&gt;
I also see my CPU is around 80% idle and working Windows OS. I have 4 Core machine 32gb ram &lt;BR /&gt;
Splunk Enterprise 6.4.3&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 18:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345648#M63497</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-09-21T18:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index data in real time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345649#M63498</link>
      <description>&lt;P&gt;Hi @chintan_shah,&lt;/P&gt;

&lt;P&gt;Are you getting any error in Splunk Universal Forwarder's splunkd.log ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harshil&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 15:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345649#M63498</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-09-27T15:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index data in real time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345650#M63499</link>
      <description>&lt;P&gt;@chintan_shah - First, please determine whether the files are not being indexed in a timely manner, or not being forwarded in a timely manner.&lt;/P&gt;

&lt;P&gt;Second, check through the debug steps at  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata#Are_you_using_forwarders."&gt;"I can't find my data"&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 19:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-data-in-real-time/m-p/345650#M63499</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-27T19:31:14Z</dc:date>
    </item>
  </channel>
</rss>

