All Apps and Add-ons

splunk not showing most recent data

eholz1
Builder

Hello All,
I have a system set up that forwards log files from multiple servers to a "syslog server".
I am using one log file on the syslog server for the data from the multiple servers. I have a universal forwarder
configured on the syslog server which forwards via TCP 9997 to the splunk enterprise server, which is running on
windows.

The issue I am having is that the latest data in my log file is not being forwarded to my splunk indexer.
I checked the forwarder via the "list forward-server" command and it shows active forwarding to the index via the 9997 port.
I checked the monitoring and it is monitoring the correct file, and the file has the latest data. The latest data is not going to the
indexer for some reason. I have restarted the services, and also restarted the Splunk server.

Any suggestions on troubleshooting?

Thanks,
eholz1

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

Hi @eholz1!

Is the data streaming in steadily just delayed? Depending on the volume of data going through your forwarder you could be hitting maxkbps. Default is 256kbps. You can change this setting on your forwarder in limits.conf. Docs for it are available here: https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Limitsconf#.5Bthruput.5D.

View solution in original post

0 Karma

eholz1
Builder

Wow, thanks fast response.
There should not be a lot of data streaming, as the file may change (maybe) only every five minutes or so.
I will check the info you provided, It will be helpful.

AND, back in the forum after checking, and changing the default to 512kbps, this seemed to do the trick.
thanks

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Hi @eholz1!

Is the data streaming in steadily just delayed? Depending on the volume of data going through your forwarder you could be hitting maxkbps. Default is 256kbps. You can change this setting on your forwarder in limits.conf. Docs for it are available here: https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Limitsconf#.5Bthruput.5D.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...