<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: data stop getting indexed for couple of hours in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379850#M68617</link>
    <description>&lt;P&gt;Probably we've figured out the root cause. Last week we indexed 20 gb for this instance within one day and have a configured thruput of 256 kb. So it was only a delayed indexing and not a "outage" of the forwarder itself.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Feb 2019 08:58:39 GMT</pubDate>
    <dc:creator>Paul1896</dc:creator>
    <dc:date>2019-02-18T08:58:39Z</dc:date>
    <item>
      <title>data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379840#M68607</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;we have problems with some log files which are randomly don't get indexed for a couple of hours. There is no log rotation during this time period and sometimes even no restart of the splunk forwarder is neccessary to start again with indexing.&lt;/P&gt;

&lt;P&gt;Output splunkd.log filtered for affected "audit_log":&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; 02-12-2019 12:09:57.358 +0100 DEBUG ChunkedLBProcessor - Chunked Line Breaker Processing has been disabled for for sourcetype::audit_log
 02-12-2019 12:09:57.358 +0100 INFO  UTF8Processor - Converting using CHARSET="UTF-8" for conf "source::/xxx/audit.log|host::xxx|Haudit_log|339419"
02-12-2019 06:33:16.783 +0100 INFO  S2SSender - Abandoning channel with code=2, conf="source::/xxx/audit.log|host::xxx|audit_log|339419", unique_id=422585, last_touched=1549948674, last_touched_asctime="Tue Feb 12 06:17:54 2019", age=922281, ttl=300000
02-12-2019 06:17:54.985 +0100 INFO  Metrics - group=per_sourcetype_thruput, series="audit_log", kbps=0.06303521503133032, eps=0.5483843194729626, kb=1.9541015625, ev=17, avg_age=0.6470588235294118, max_age=5
02-12-2019 06:17:54.503 +0100 DEBUG TcpOutputProc - Pushed eventId=61 on chanId=422585 to back of tcp client (tcp output) queue. source:source::/xxx/audit.log|host::xxx|audit_log|339419
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Feb 2019 13:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379840#M68607</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2019-02-12T13:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379841#M68608</link>
      <description>&lt;P&gt;If there is log rotation and you do not have some kind of housekeeping setup to delete the older files, the Splunk forwarder will get slower and slower and slower.  Once you hit thousands of files in the same directory, Splunk will seem to stop forwarding completely.  You have to keep the number of dead files low.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 16:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379841#M68608</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-12T16:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379842#M68609</link>
      <description>&lt;P&gt;Hey @woodcock thanks for your reply! We have a housekeeping in place and the monitor doesn't match the older logs which are already rotated. So in my understanding the size &amp;amp; total of files of/in the folder itself isn't important in case if your monitor just indexing a specified logfile in it. Please correct me if I'm wrong. We also facing the problem only from time to time and after a while or a reboot the logging works without any problems.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 07:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379842#M68609</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2019-02-13T07:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379843#M68610</link>
      <description>&lt;P&gt;Your understanding is completely wrong.  Even though the rotated files do not match the monitor stanza, they still have a deadly impact on the forwarder.  Splunk still has to sort through them and when they pile up, Splunk performance will crater.  Restarting Splunk causes it to work for a short short spurt and then it goes right back to poor performance.  Here is an easy way to fix it.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/309910/how-to-monitor-a-folder-for-newest-files-only-file.html"&gt;https://answers.splunk.com/answers/309910/how-to-monitor-a-folder-for-newest-files-only-file.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 16:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379843#M68610</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-13T16:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379844#M68611</link>
      <description>&lt;P&gt;What version of Splunk are you using?  There are some v6 releases that have big problems like this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/549663/splunk-661-stops-monitoring-files.html#answer-718797"&gt;https://answers.splunk.com/answers/549663/splunk-661-stops-monitoring-files.html#answer-718797&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 17:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379844#M68611</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-13T17:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379845#M68612</link>
      <description>&lt;P&gt;@Paul1896 - about how many files we are talking about on this path? &lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 18:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379845#M68612</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-02-13T18:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379846#M68613</link>
      <description>&lt;P&gt;@ddrillic We're talking  just about 220 files&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 13:35:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379846#M68613</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2019-02-14T13:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379847#M68614</link>
      <description>&lt;P&gt;We're using Splunk 7.1.5&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 13:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379847#M68614</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2019-02-14T13:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379848#M68615</link>
      <description>&lt;P&gt;If that's the case, the number of files couldn't be the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 15:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379848#M68615</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-02-14T15:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379849#M68616</link>
      <description>&lt;P&gt;It can if the &lt;CODE&gt;depth&lt;/CODE&gt; is not limited.  Are there any &lt;CODE&gt;...&lt;/CODE&gt; in the file path?  Are there hundreds of other potential path points with many files in them?  This can still be the problem!!!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 21:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379849#M68616</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-14T21:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379850#M68617</link>
      <description>&lt;P&gt;Probably we've figured out the root cause. Last week we indexed 20 gb for this instance within one day and have a configured thruput of 256 kb. So it was only a delayed indexing and not a "outage" of the forwarder itself.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 08:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379850#M68617</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2019-02-18T08:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: data stop getting indexed for couple of hours</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379851#M68618</link>
      <description>&lt;P&gt;That would definitely do it.  Please click &lt;CODE&gt;Accept&lt;/CODE&gt; here to close the question.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 09:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/data-stop-getting-indexed-for-couple-of-hours/m-p/379851#M68618</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-06T09:16:04Z</dc:date>
    </item>
  </channel>
</rss>

