<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log forwarding not every 30 seconds in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538248#M90229</link>
    <description>&lt;P&gt;ah I understand.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When you have added a new input stanza, and restartet the service for it to load properly.&lt;BR /&gt;You nedd to restart the Universal Forwarder to make it reload the setting.&lt;BR /&gt;&lt;BR /&gt;Are you using windows or Linux?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Every time Splunk boots or is restarted it is written the output into a splunkd.log file.&lt;BR /&gt;This could be checked with nano or notepad, depending on youre operativsystem.&amp;nbsp;&lt;BR /&gt;If there is any problem during startup, perhaps an error in the input settings, it would be in there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You recieved at a earlier stage a new event every 30 second, I would check those events and find out what type of info it is.&amp;nbsp; Then I would check the file on the server that you got the event from and double cheeck that the file is updatet every 30 second.&amp;nbsp;&lt;BR /&gt;Spluk dont make the logs, it is just gathering the logs. So iI think therefore maybe a application updatet the logfile every 30 sconds.&amp;nbsp; But this you need to check manually.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Perhaps you could make a scheduled or cron job to update a txt file with a timestamp every 30 second just to make sure that everything is in order, for testing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck&lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2021 09:38:11 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2021-02-02T09:38:11Z</dc:date>
    <item>
      <title>Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538071#M90190</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;As far as I know, forwarder must forward logs to indexer every 30 seconds.&lt;/P&gt;&lt;P&gt;I've reinstalled system and trying to configure it.&lt;/P&gt;&lt;P&gt;I opened 9997 port on indexer for receiving, and did ./splunk add forward-server ip and ./splunk add monitor /var/log&lt;/P&gt;&lt;P&gt;Logs collecting, it's alright, but not every 30 seconds, no errors in logs&lt;/P&gt;&lt;P&gt;what can cause this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 11:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538071#M90190</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2021-02-01T11:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538086#M90196</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228794"&gt;@bosseres&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Forwarders sends logs to indexers immediately, they do not wait 30 seconds. Maybe you are confusing with auto load balance period which is 30 seconds default. Since you have only one indexer this is not valid.&lt;/P&gt;&lt;P&gt;Any log file change in /var/log path should be immediately sent to indexer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 13:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538086#M90196</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-01T13:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538093#M90201</link>
      <description>&lt;P&gt;The default interval is 60 seconds.&amp;nbsp; Look in $SPLUNK_HOME/etc/system/local to see the setting for /var/log and to change it, if desired.&amp;nbsp; Remember to restart the forwarder if you change the setting.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:20:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538093#M90201</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-01T14:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538094#M90202</link>
      <description>&lt;P&gt;how can I set interval?&lt;/P&gt;&lt;P&gt;I put in inputs.conf but this not helped&lt;/P&gt;&lt;P&gt;[perfmon:///var/log]&lt;BR /&gt;interval = 30&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538094#M90202</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2021-02-01T14:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538095#M90203</link>
      <description>&lt;P&gt;Yes forwarder is working, it sends data when some event occured, but I want configure to send data every 30 seconds, even if there are no events&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538095#M90203</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2021-02-01T14:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538104#M90208</link>
      <description>&lt;P&gt;Did you restart the forwarder after changing props.conf?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 15:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538104#M90208</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-01T15:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538220#M90226</link>
      <description>&lt;P&gt;Yes, I did, but i m not sure that i've changed parameter which I should&lt;/P&gt;&lt;P&gt;can you say what exactly should I change there? thank you&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 07:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538220#M90226</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2021-02-02T07:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538235#M90227</link>
      <description>&lt;P&gt;If there are no new events, what type of data would you like it to send?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you want to use it like a heartbeat to warn if a client is missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 08:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538235#M90227</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-02-02T08:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538238#M90228</link>
      <description>&lt;P&gt;Yes, I just study working with Splunk, and want to be sure that events are collecting&lt;/P&gt;&lt;P&gt;By the way, if I don't miss something, earlier my indexer got events every 30 seconds, thats why I want to return it&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 09:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538238#M90228</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2021-02-02T09:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding not every 30 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538248#M90229</link>
      <description>&lt;P&gt;ah I understand.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When you have added a new input stanza, and restartet the service for it to load properly.&lt;BR /&gt;You nedd to restart the Universal Forwarder to make it reload the setting.&lt;BR /&gt;&lt;BR /&gt;Are you using windows or Linux?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Every time Splunk boots or is restarted it is written the output into a splunkd.log file.&lt;BR /&gt;This could be checked with nano or notepad, depending on youre operativsystem.&amp;nbsp;&lt;BR /&gt;If there is any problem during startup, perhaps an error in the input settings, it would be in there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You recieved at a earlier stage a new event every 30 second, I would check those events and find out what type of info it is.&amp;nbsp; Then I would check the file on the server that you got the event from and double cheeck that the file is updatet every 30 second.&amp;nbsp;&lt;BR /&gt;Spluk dont make the logs, it is just gathering the logs. So iI think therefore maybe a application updatet the logfile every 30 sconds.&amp;nbsp; But this you need to check manually.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Perhaps you could make a scheduled or cron job to update a txt file with a timestamp every 30 second just to make sure that everything is in order, for testing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 09:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-forwarding-not-every-30-seconds/m-p/538248#M90229</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-02-02T09:38:11Z</dc:date>
    </item>
  </channel>
</rss>

