<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs missing in splunk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579966#M8753</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239231"&gt;@kharade0009&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe the zip file isn't continously updated but it's created and updated in one shot, so your UF read the zip file content in one shot and you index logs in one shot and not in continous way.&lt;/P&gt;&lt;P&gt;See if you can continously write logs in the file system instead in one shot in the zip file, otherwise I think that you can do few.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jan 2022 09:28:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-01-05T09:28:56Z</dc:date>
    <item>
      <title>logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579824#M8744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have configure splunk forwarder to send logs to splunk on 6 servers.logs are psuhing to the splunk for sometimes.but for it gets stop for some hours and again it gets restarted after some hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can someone help to gets the exact issue here?&lt;/P&gt;&lt;P&gt;input.conf&lt;/P&gt;&lt;P&gt;[monitor:///var/log/application/*.log]&lt;BR /&gt;sourcetype = app-us-west&lt;BR /&gt;index = us_west&lt;/P&gt;&lt;P&gt;disabled = false&lt;BR /&gt;recursive = true&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;output.conf&lt;/P&gt;&lt;P&gt;indexAndForward]&lt;BR /&gt;index = false&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = default&lt;BR /&gt;forwardedindex.filter.disable = true&lt;BR /&gt;indexAndForward = false&lt;/P&gt;&lt;P&gt;[tcpout:default]&lt;BR /&gt;autoLB = true&lt;BR /&gt;autoLBFrequency = 30&lt;BR /&gt;forceTimebasedAutoLB = true&lt;BR /&gt;server = splunk-fwd-:9997&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;limits.conf&lt;/P&gt;&lt;P&gt;maxKBps = 0&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 05:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579824#M8744</guid>
      <dc:creator>kharade0009</dc:creator>
      <dc:date>2022-01-04T05:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579841#M8745</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239231"&gt;@kharade0009&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;by default, Splunk UF continously forwards logs, so if you have a pause in forwarding, with the only exception of scripted inputs, this could be caused by external problems as network congestion.&lt;/P&gt;&lt;P&gt;In addition, you should check the upgrade frequency of your data source: maybe they are't continously&amp;nbsp; upgraded.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 08:02:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579841#M8745</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-04T08:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579853#M8746</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Data being updated for other sourcetypes.We are using three source types with single indexer.&lt;/P&gt;&lt;P&gt;Data is not getting updated only for one sourcetype.Also for this sourcetype application logs which we are forwarding are zipping because of log rotation. I can see mismatch at the time of log rotation of the log file.&lt;/P&gt;&lt;P&gt;but issue is intermittent. anything else could be the issue other than network?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 11:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579853#M8746</guid>
      <dc:creator>kharade0009</dc:creator>
      <dc:date>2022-01-04T11:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579882#M8747</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239231"&gt;@kharade0009&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're continously receiving data of other sourcetypes from the same machine, the problem isn't a network congestion.&lt;/P&gt;&lt;P&gt;So analyze your data source to understand the reason of the pauses.&lt;/P&gt;&lt;P&gt;Only one question: you said that the logs are zipped, but could you take the logs before zipping instead of zipped logs?&lt;/P&gt;&lt;P&gt;If you configured your input to take only zipped logs, probably this is the problem.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 14:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579882#M8747</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-04T14:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579913#M8751</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my inputs.conf file I have mentioned as&amp;nbsp;monitor:///var/log/application/*.log.&lt;/P&gt;&lt;P&gt;My log are creating as app-stats.2022-01-04-101.log.gz zip file.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It seems it is taking my .log file only.not sure if any thing wrong with indexer or AutoLB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 19:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579913#M8751</guid>
      <dc:creator>kharade0009</dc:creator>
      <dc:date>2022-01-04T19:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: logs missing in splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579966#M8753</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239231"&gt;@kharade0009&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe the zip file isn't continously updated but it's created and updated in one shot, so your UF read the zip file content in one shot and you index logs in one shot and not in continous way.&lt;/P&gt;&lt;P&gt;See if you can continously write logs in the file system instead in one shot in the zip file, otherwise I think that you can do few.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 09:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/logs-missing-in-splunk/m-p/579966#M8753</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-05T09:28:56Z</dc:date>
    </item>
  </channel>
</rss>

