All Apps and Add-ons

Is it possible to Backfill vmware Data?

SonOfBuzi
Loves-to-Learn Everything

I have a DCS with Splunk Add-on for VMware with 2 DCN. For some reason, it stopped ingesting data for two days. Is it possible to backfill the data for the two days it missed?

Labels (2)
Tags (1)
0 Karma

shivanshu1593
Builder

If you can send that data to Splunk, it should be able to handle it. It will create appropriate buckets and index the data. You'll find error messages like the following in the splunkd.log, but you can ignore them.

 

A possible timestamp match (Tue May 23 08:01:43 2022) is outside of the acceptable time window.

• Accepted time (Tue May 23 00:33:16 2022) is suspiciously far away from the previous event's time (Thu May 25 14:10:32 2022), but still acceptable because it was extracted by the same pattern Splunk

• Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (128) characters of the event. Splunk

 

 

You can also look into increasing the values for MAX_DIFF_SECS_AGO in props.conf for this sourcetype or just ignore the errors. Your call.

###If this helps, kindly consider accepting as an answer###

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

SonOfBuzi
Loves-to-Learn Everything

My question is if it's possible to backfill data with the the splunk add-on for vmware as far as my research goes it's not possible maybe will add it as a feature request

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...