<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196824#M7928</link>
    <description>&lt;P&gt;They are from same sourcetype. There is no commanlity.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Aug 2014 14:52:13 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-08-27T14:52:13Z</dc:date>
    <item>
      <title>Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196822#M7926</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;One of our customers is using Splunk 5.0.4. The log files are forwarded to indexer using Splunk Universal Forwarder.&lt;/P&gt;

&lt;P&gt;The log in flow is like this:&lt;BR /&gt;&lt;BR /&gt;
Splunk UF on Devices --&amp;gt; Splunk UF in the product --&amp;gt; Indexer&lt;/P&gt;

&lt;P&gt;The issue is: At times, some log events are not getting indexed and this leads to data inaccuracy in our metrics. Recently when they reported this issue, i took log files from them and indexed them in my local test bed. I was able to replicate the issue. Out of 5000 log events, 7 events did not enter the index. Similarly in other log file, out of 5085 log events, 13 events did not enter the index.&lt;/P&gt;

&lt;P&gt;I checked following:&lt;BR /&gt;&lt;BR /&gt;
 1. If log event length is on the higher side -- answer is No.&lt;BR /&gt;&lt;BR /&gt;
 2. If some unreasonable junk characters are present in the log event -- answer is No.&lt;BR /&gt;&lt;BR /&gt;
 3. If the log events are duplicate of other log events -- answer is No.&lt;/P&gt;

&lt;P&gt;Could you suggest some pointers for me to troubleshoot this issue. Why some specific log lines are not getting indexed?&lt;/P&gt;

&lt;P&gt;Note: This is not happening all the time. In last two weeks this has happened twice for around 10 log files.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;
Strive&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 12:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196822#M7926</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-27T12:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196823#M7927</link>
      <description>&lt;P&gt;Are they the same sourcetype or different? Also, is there any commonality among the events that are not getting indexed?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 13:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196823#M7927</guid>
      <dc:creator>jbouch03</dc:creator>
      <dc:date>2014-08-27T13:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196824#M7928</link>
      <description>&lt;P&gt;They are from same sourcetype. There is no commanlity.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 14:52:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196824#M7928</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-27T14:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196825#M7929</link>
      <description>&lt;P&gt;Created a log file using the missing events alone and tried indexing this file. The events are not getting indexed, there are no errors in splunkd.log (enabled debug mode and checked). Manually verified every field in the log file, it all looks fine.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 20:48:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196825#M7929</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-27T20:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196826#M7930</link>
      <description>&lt;P&gt;Would it be possible for you to share those events which are not getting indexed? (may after masking sensitive information), Also, the sourcetype definition (props.conf)?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 21:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196826#M7930</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-27T21:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196827#M7931</link>
      <description>&lt;P&gt;Link to files&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/5g8q4d40j5mwf2b/my_data.13.13.13.13_20140823_114500_1501?dl=0" target="_blank"&gt;https://www.dropbox.com/s/5g8q4d40j5mwf2b/my_data.13.13.13.13_20140823_114500_1501?dl=0&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;[my_source_type]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TRANSFORMS-include = some transforms&lt;BR /&gt;
TIME_PREFIX=^([^\t]*\t){2}&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD=35&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196827#M7931</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2020-09-28T17:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196828#M7932</link>
      <description>&lt;P&gt;any &lt;CODE&gt;nullQueue&lt;/CODE&gt; in any &lt;CODE&gt;transforms.conf&lt;/CODE&gt; which could interfere here? check with btool&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 12:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196828#M7932</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-28T12:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196829#M7933</link>
      <description>&lt;P&gt;Are the log files rolling? If so, check if the events are being missed for some reason while the log is being rolled.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 13:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196829#M7933</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-08-28T13:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196830#M7934</link>
      <description>&lt;P&gt;try to index the events again while running this script &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 13:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196830#M7934</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-28T13:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196831#M7935</link>
      <description>&lt;P&gt;The log files are not rolling.&lt;BR /&gt;
We have set nullQueue for headers. This wont interfere with these log lines.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 17:21:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196831#M7935</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-28T17:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why are certain log events not getting indexed in Splunk 5.0.4 and how to troubleshoot?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196832#M7936</link>
      <description>&lt;P&gt;The log files had secondary header line starting with words s-ip|#Fields.&lt;BR /&gt;&lt;BR /&gt;
If the log lines had any field value(s) with s-ip as substring then those log lines were stripped off. &lt;BR /&gt;
We had to modify our transforms.conf configurations to address this issue.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2014 17:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-certain-log-events-not-getting-indexed-in-Splunk-5-0-4/m-p/196832#M7936</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-31T17:58:24Z</dc:date>
    </item>
  </channel>
</rss>

