<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: delayed logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522577#M88263</link>
    <description>&lt;P&gt;In a previous post you suggested that I check that it will have a minimum IOPS, after checking, the disk has more than 800, it even has double.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2020 19:12:16 GMT</pubDate>
    <dc:creator>splunkcol</dc:creator>
    <dc:date>2020-10-01T19:12:16Z</dc:date>
    <item>
      <title>delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522511#M88236</link>
      <description>&lt;P&gt;I have a problem with the logs, they are arriving with a delay of 12 hours or more&lt;/P&gt;&lt;P&gt;The information first reaches a syslog server and is forwarded to the indexers&lt;/P&gt;&lt;P&gt;When reviewing the logs in the syslog servers I find that they arrive without problem and with the correct date and time&lt;/P&gt;&lt;P&gt;when I go to the indexers or search heads to look at the logs I see that they have a delay of 12 hours or more&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this document I have tried to diagnose the problem but I cannot find the same panels that ask to review the document&lt;/P&gt;&lt;P&gt;in the part where it is suggested to check with the command iostat -zx 1 one of the parameters are in the values ​​cataloged as bad&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/pdfs/technical-briefs/disk-diagnosis-digging-deep-with-monitoring-console-and-more.pdf" target="_blank" rel="noopener"&gt;https://www.splunk.com/pdfs/technical-briefs/disk-diagnosis-digging-deep-with-monitoring-console-and-more.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_1-1601562510064.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11076iA9ADACD4A916C2A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunkcol_1-1601562510064.png" alt="splunkcol_1-1601562510064.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="splunkcol_0-1601561959333.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11075iD935EDC35D6C83B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1601561959333.png" alt="splunkcol_0-1601561959333.png" /&gt;&lt;/span&gt;&lt;SPAN&gt;What else should I check?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_2-1601562619818.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11077i87E365F595AC68C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_2-1601562619818.png" alt="splunkcol_2-1601562619818.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 14:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522511#M88236</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-10-01T14:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522513#M88237</link>
      <description>How you are reading and forwarding those logs from syslog server? One issue could be that if/when you are using UF, you are hitting is't max default capacity?&lt;BR /&gt;This is good starting point for looking this issue: &lt;A href="https://conf.splunk.com/files/2019/slides/FN1570.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1570.pdf&lt;/A&gt;&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 01 Oct 2020 14:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522513#M88237</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T14:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522569#M88259</link>
      <description>&lt;P&gt;yes, the syslog server receives the logs and forwards them to the indexers using UF&lt;/P&gt;&lt;P&gt;I understand that the cause of the queuing is typingqueue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1601577492282.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11084i824946B85BCAD173/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1601577492282.png" alt="splunkcol_0-1601577492282.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 18:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522569#M88259</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-10-01T18:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522575#M88261</link>
      <description>In your first message it shows that your disk io utilization is 100%. This means that it cannot handle more traffic without adding more disk to get more performance.&lt;BR /&gt;What kind of disk you have and what is amount of your daily/peak indexing volume?</description>
      <pubDate>Thu, 01 Oct 2020 19:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522575#M88261</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T19:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522577#M88263</link>
      <description>&lt;P&gt;In a previous post you suggested that I check that it will have a minimum IOPS, after checking, the disk has more than 800, it even has double.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 19:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522577#M88263</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-10-01T19:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: delayed logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522580#M88265</link>
      <description>Splunk’s requirements is minimum 800 IOPS per disk to working. But it’s just minimum. Reality is totally dependent how much you are ingesting and what kind of query load you have. Here is link to reference hardware &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Capacity/Referencehardware" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Capacity/Referencehardware&lt;/A&gt;</description>
      <pubDate>Thu, 01 Oct 2020 19:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/delayed-logs/m-p/522580#M88265</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T19:21:19Z</dc:date>
    </item>
  </channel>
</rss>

