<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Late indexed in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744594#M10892</link>
    <description>&lt;P&gt;Does the script send to HEC or write to a file? If HEC - which endpoint?&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2025 18:59:08 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-04-21T18:59:08Z</dc:date>
    <item>
      <title>Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744546#M10885</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue Description&lt;/STRONG&gt;&lt;BR /&gt;We are experiencing a significant delay in data ingestion (&amp;gt;10 hours) for one index in Project B within our Splunk environment. Interestingly, Project A, which operates with a nearly identical configuration, does not exhibit this issue, and data ingestion occurs as expected.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps Taken to Diagnose the Issue&lt;/STRONG&gt;&lt;BR /&gt;To identify the root cause of the delayed ingestion in Project B, the following checks were performed:&lt;/P&gt;&lt;P&gt;Timezone Consistency: Verified that the timezone settings on the database server (source of the data) and the Splunk server are identical, ruling out timestamp misalignment.&lt;/P&gt;&lt;P&gt;Props Configuration: Confirmed that the props.conf settings align with the event patterns, ensuring proper event parsing and processing.&lt;/P&gt;&lt;P&gt;System Performance: Monitored CPU performance on the Splunk server and found no resource bottlenecks or excessive load.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note :&lt;/STRONG&gt; Configuration Comparison: Conducted a thorough comparison of configurations between Project A and Project B, including inputs, outputs, and indexing settings, and found no apparent differences.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Observations&lt;/STRONG&gt;&lt;BR /&gt;The issue is isolated to Project B, despite both projects sharing similar configurations and infrastructure.&lt;/P&gt;&lt;P&gt;Project A processes data without delays, indicating that the Splunk environment and database connectivity are generally functional.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Screenshot 1 :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1745211229899.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38663i63D37A57EC122B8F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1745211229899.png" alt="uagraw01_0-1745211229899.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Screenshot 2 :&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1745211284326.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38664iC6159289979F6B42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1745211284326.png" alt="uagraw01_1-1745211284326.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Event sample :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;TIMESTAMP="2025-04-17T21:17:05.868000Z",SOURCE="TransportControllerManager_x.onStatusChangedTransferRequest",IDEVENT="1312670",EVENTTYPEKEY="TRFREQ_CANCELLED",INSTANCEID="210002100",OBJECTTYPE="TRANSFERREQUEST",OPERATOR="1",OPERATORID="1",TASKID="10030391534",TSULABEL="309360376000158328"&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[wmc_events]&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;CHARSET=AUTO&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;KV_MODE=AUTO&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;SHOULD_LINEMERGE=false&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;description= WMC events received from the Oracle database, formatted as key-value pairs&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;pulldown_type=true&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TIME_PREFIX = ^TIMESTAMP=&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%6NZ&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TZ = UTC&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;NO_BINARY_CHECK = true&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TRUNCATE = 10000000&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;#MAX_EVENTS = 100000&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ANNOTATE_PUNCT = false&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 04:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744546#M10885</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-04-21T04:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744552#M10886</link>
      <description>&lt;P&gt;Could this be that the file you are monitoring on the database server has not been closed / flushed so the forwarder is unaware of any updates until later?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 08:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744552#M10886</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-04-21T08:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744553#M10887</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; Data flushing is enabled for the required tables.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 09:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744553#M10887</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-04-21T09:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744584#M10888</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its very suspicious that the time looks to be ~ - 36000 seconds - being pretty much *exactly* 10 hours.&lt;/P&gt;&lt;P&gt;Could there be an issue with timezones here? It doesnt sound like the data is blocked for exactly 10 hours in the data ingestion pipeline, it feels more likely that a previous server in the ingestion journey has an incorrect timezone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The timezone set in props.conf for the given sourcetype (TZ=) will be used based on the "&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.1/Admin/Propsconf#:~:text=use%20the%20timezone%20provided%0A%20%20by%20the%20forwarder" target="_self"&gt;the timezone provided by the forwarder.&lt;/A&gt;" - Its worth checking if the forwarder in Project B, assuming this is different to Project A?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744584#M10888</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-21T15:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744591#M10889</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;Both the servers are in the same timezone. As I already compared the timezone setting on Project A and B.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744591#M10889</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-04-21T18:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744592#M10890</link>
      <description>&lt;P&gt;Wait a second. File or table? What kind of source does this data come from? Monitor input? Dbconnect?&lt;/P&gt;&lt;P&gt;Have you checked the actual data with someone responsible for the source? I mean whether the ID or whatever it is in your data corresponds to the right timestamp?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744592#M10890</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-04-21T18:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744593#M10891</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;SPAN&gt;A Python script is designed to establish a connection with the Oracle database, extract data from designated tables, and forward the retrieved data into Splunk for ingestion.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:48:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744593#M10891</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-04-21T18:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744594#M10892</link>
      <description>&lt;P&gt;Does the script send to HEC or write to a file? If HEC - which endpoint?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:59:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744594#M10892</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-04-21T18:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Late indexed</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744871#M10893</link>
      <description>&lt;P class="lia-align-left"&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;, Just an update to you.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P class=""&gt;We have identified and resolved an issue related to a time discrepancy in our system, which was caused by the Oracle server's timezone configuration. The server was set to local time instead of UTC, resulting in a 10-hour time difference that affected [specific process, application, or data].&lt;/P&gt;&lt;P class=""&gt;To address this, we have reconfigured the Oracle server to use UTC as the standard timezone, ensuring consistency and alignment with our operational requirements. This change has eliminated the time discrepancy, and all affected processes are now functioning as expected.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Apr 2025 08:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Late-indexed/m-p/744871#M10893</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-04-24T08:51:53Z</dc:date>
    </item>
  </channel>
</rss>

