All Apps and Add-ons

Is it possible to Backfill vmware Data?

SonOfBuzi
Loves-to-Learn Lots

I have a DCS with Splunk Add-on for VMware with 2 DCN. For some reason, it stopped ingesting data for two days. Is it possible to backfill the data for the two days it missed?

Labels (2)
Tags (1)
0 Karma

shivanshu1593
Builder

If you can send that data to Splunk, it should be able to handle it. It will create appropriate buckets and index the data. You'll find error messages like the following in the splunkd.log, but you can ignore them.

 

A possible timestamp match (Tue May 23 08:01:43 2022) is outside of the acceptable time window.

• Accepted time (Tue May 23 00:33:16 2022) is suspiciously far away from the previous event's time (Thu May 25 14:10:32 2022), but still acceptable because it was extracted by the same pattern Splunk

• Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (128) characters of the event. Splunk

 

 

You can also look into increasing the values for MAX_DIFF_SECS_AGO in props.conf for this sourcetype or just ignore the errors. Your call.

###If this helps, kindly consider accepting as an answer###

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

SonOfBuzi
Loves-to-Learn Lots

My question is if it's possible to backfill data with the the splunk add-on for vmware as far as my research goes it's not possible maybe will add it as a feature request

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...