Dashboards & Visualizations

Continuous CAT to Splunk Logs Failing to host = 161.209.202.108, user = sv_cat, port = 22

Praz_123
Communicator

CAT to Splunk Logs Failing:
host = 161.209.202.108
user = sv_cat
port = 22

Start time: 10/24/2023 at 4:21am 

Tags (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Is there a question or are you just reporting this? If it is a question, you should provide more information about what you have tried, and what the actual errors are.

0 Karma

Praz_123
Communicator

 
Basically, this is a question , able to see events till 4:00 am and after that not able to see.

With the below query able to check the last events :-

| tstats  count where index=cat by host, index, source, sourcetype, _time

| search host=* |sort _time

@ITWhisperer

Tags (3)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

>>>Basically, this is a question , able to see events till 4:00 am and after that not able to see.

Hi @Praz_123 ... you were able to see logs/events till 4am and then not able to see, (for the host with ip  161.209.202.108... next time please avoid the ip addresses in your post, for security concerns)

maybe... there are not events/logs after 4am at all.

so, you should check the team or person who creates those events/logs(at the required host)

 

Iif you are looking for more details, Pls update us with more info, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Basically, still not a question. If it is a question, what sort of answer are you expecting?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...