Deployment Architecture

Search Heads not parsing unexpectedly



I need some help where to look in order to diagnostic the issue I am facing.

I am using v8.0.9 in a multisite search head cluster and indexer cluster. After more than 30 days of normal operation, the search heads are not parsing bluecoat logs. While I try the same search from the cluster master the parsing is done properly but from any of the search heads....

There has not done any change in the cluster but suddenly the parsing stopped working.

Any ideas on where to focus my troubleshooting?

Labels (1)
0 Karma



When you say parsing on search heads, do you mean search time extraction is not working on Search Heads for Bluecoat logs ?

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...