All Apps and Add-ons

Are there time look back limitations when exporting data from Splunk Hadoop Connect?

_gkollias
SplunkTrust
SplunkTrust

Hi!

While using Splunk Hadoop Connect to export data from Splunk to Hadoop, we've observed export functionality halts once we reach 254 days ago. We have 14 months of summary data that we'd like to export, but are unable to go back any further.

Here are some references in the documentation we've been using to test:

http://docs.splunk.com/Documentation/HadoopConnect/1.2.5/DeployHadoopConnect/Configurationfilerefere...

https://docs.splunk.com/Documentation/HadoopConnect/1.2.5/DeployHadoopConnect/ExporttoHDFS#How_data_...

Also, we've also made sure to stay in line with file size limitations. Are there any known limitations to how far back we can go to export data? Any insight is greatly appreciated.

Thanks in advance!

0 Karma
1 Solution

sloshburch
Splunk Employee
Splunk Employee

Sounds like either a bug or other symptoms we've not yet seen:

  • Bug: Open a Support Case since it's not working as documented
  • Error Message: Before support case, make sure there's no error messages in _internal or the related sources from the hadoop connect. It's possible Splunk is dying on something related to the content and we just didn't notice that error.

Lastly, there are some alternatives to this functionality depending on the purpose of using it:

(I thought there was more, but now my mind is blank, so we'll start with this).

View solution in original post

sloshburch
Splunk Employee
Splunk Employee

Sounds like either a bug or other symptoms we've not yet seen:

  • Bug: Open a Support Case since it's not working as documented
  • Error Message: Before support case, make sure there's no error messages in _internal or the related sources from the hadoop connect. It's possible Splunk is dying on something related to the content and we just didn't notice that error.

Lastly, there are some alternatives to this functionality depending on the purpose of using it:

(I thought there was more, but now my mind is blank, so we'll start with this).

Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...