<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to get the recent logs - error in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752158#M11009</link>
    <description>&lt;P&gt;What product? Logs from where? What exactly are you doing?&amp;nbsp;Where do you get this message?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Aug 2025 17:29:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-08-25T17:29:13Z</dc:date>
    <item>
      <title>unable to get the recent logs - error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752128#M11008</link>
      <description>&lt;P&gt;Unable to get the recent logs for today for an production environment. It is throwing an error stating "&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;PropertyMaker&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt; &lt;SPAN class=""&gt;length&lt;/SPAN&gt; &lt;SPAN class=""&gt;unit&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;E-15&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;How to get the recent logs in splunk? Please help&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 14:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752128#M11008</guid>
      <dc:creator>isahu</dc:creator>
      <dc:date>2025-08-25T14:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: unable to get the recent logs - error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752158#M11009</link>
      <description>&lt;P&gt;What product? Logs from where? What exactly are you doing?&amp;nbsp;Where do you get this message?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 17:29:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752158#M11009</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-25T17:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: unable to get the recent logs - error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752160#M11010</link>
      <description>&lt;P&gt;I onboarded a new application log in splunk but after onboarding this application I noticed recent logs are missing a day before logs are available but not the recent ones. While checking logs in splunk search head I am getting this error.&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;PropertyMaker&lt;/SPAN&gt;&lt;SPAN&gt;]&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;length&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;unit&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;E-15&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 17:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752160#M11010</guid>
      <dc:creator>isahu</dc:creator>
      <dc:date>2025-08-25T17:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: unable to get the recent logs - error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752161#M11011</link>
      <description>&lt;P&gt;More details would help us better understand the problem so can offer solutions.&lt;/P&gt;&lt;P&gt;If recent logs are not found in Splunk then try these steps&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;confirm the application is still running&lt;/LI&gt;&lt;LI&gt;confirm the Splunk forwarder is still running&lt;/LI&gt;&lt;LI&gt;If the application overwrites the file then it's possible Splunk thinks it has already indexed the data.&amp;nbsp; In that case, you may need to update the &lt;FONT face="courier new,courier"&gt;initCrcLenth&lt;/FONT&gt; setting in inputs.conf.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 25 Aug 2025 17:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/unable-to-get-the-recent-logs-error/m-p/752161#M11011</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-08-25T17:44:36Z</dc:date>
    </item>
  </channel>
</rss>

