<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk data forwarding and indexing data drop issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473197#M99693</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm facing issue with data forwarding to splunk. i'm not sure where data being dropped and its happening randomly.&lt;BR /&gt;
Details:&lt;BR /&gt;
I have text (key-value pair) file with 6.5 million lines(events) with same timestamp (_time) configured. &lt;BR /&gt;
but while ingesting file to splunk via Heavy forwarder, it automatically incrementing _time +1 sec for every 100k or 200k events  randomly.&lt;BR /&gt;
Observation:&lt;BR /&gt;
if the _time +1 sec  increment happens  for every 100k events, then no issues data completely ingest to splunk.&lt;BR /&gt;
if some times _time +1 sec increment happens for 200+k events, we are observing data drop, only 4 to 4.5 million events got ingested out of 6.5 million events.&lt;/P&gt;

&lt;P&gt;splunk log giving this warning:&lt;BR /&gt;
WARN  DateParserVerbose - The same timestamp has been used for 500K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable&lt;/P&gt;

&lt;P&gt;Splunk Environment details:&lt;BR /&gt;
Splunk Version: 7.2.6&lt;BR /&gt;
OS: AWS Linux Machine&lt;/P&gt;

&lt;P&gt;Could you please advice what is root cause of this issue and remedy for same.&lt;/P&gt;

&lt;P&gt;Thanks In Advance !!!.&lt;BR /&gt;
Mani&lt;/P&gt;</description>
    <pubDate>Fri, 01 Nov 2019 02:33:14 GMT</pubDate>
    <dc:creator>manikandankasi</dc:creator>
    <dc:date>2019-11-01T02:33:14Z</dc:date>
    <item>
      <title>Splunk data forwarding and indexing data drop issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473197#M99693</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm facing issue with data forwarding to splunk. i'm not sure where data being dropped and its happening randomly.&lt;BR /&gt;
Details:&lt;BR /&gt;
I have text (key-value pair) file with 6.5 million lines(events) with same timestamp (_time) configured. &lt;BR /&gt;
but while ingesting file to splunk via Heavy forwarder, it automatically incrementing _time +1 sec for every 100k or 200k events  randomly.&lt;BR /&gt;
Observation:&lt;BR /&gt;
if the _time +1 sec  increment happens  for every 100k events, then no issues data completely ingest to splunk.&lt;BR /&gt;
if some times _time +1 sec increment happens for 200+k events, we are observing data drop, only 4 to 4.5 million events got ingested out of 6.5 million events.&lt;/P&gt;

&lt;P&gt;splunk log giving this warning:&lt;BR /&gt;
WARN  DateParserVerbose - The same timestamp has been used for 500K consecutive times.  If more than 200K events have the same timestamp, not all events may be retrieveable&lt;/P&gt;

&lt;P&gt;Splunk Environment details:&lt;BR /&gt;
Splunk Version: 7.2.6&lt;BR /&gt;
OS: AWS Linux Machine&lt;/P&gt;

&lt;P&gt;Could you please advice what is root cause of this issue and remedy for same.&lt;/P&gt;

&lt;P&gt;Thanks In Advance !!!.&lt;BR /&gt;
Mani&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 02:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473197#M99693</guid>
      <dc:creator>manikandankasi</dc:creator>
      <dc:date>2019-11-01T02:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data forwarding and indexing data drop issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473198#M99694</link>
      <description>&lt;P&gt;I'll suggest here to fix timestamp at source (which is generating this log) so that it will be unique for every event (For example  include milliseconds in your timestamp), it will be helpful for few scenario while searching those data.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 08:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473198#M99694</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-11-01T08:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data forwarding and indexing data drop issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473199#M99695</link>
      <description>&lt;P&gt;Your sourcetype is not properly extracting the timestamp, OR...your log entries do not include milliseconds.&lt;BR /&gt;
In either case, Splunk cannot determine unique events, and generates the messages you described.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 05:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-data-forwarding-and-indexing-data-drop-issue/m-p/473199#M99695</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-11-15T05:40:15Z</dc:date>
    </item>
  </channel>
</rss>

