Deployment Architecture

Search Heads not parsing unexpectedly

adidibra
Engager

Hello,

I need some help where to look in order to diagnostic the issue I am facing.

I am using v8.0.9 in a multisite search head cluster and indexer cluster. After more than 30 days of normal operation, the search heads are not parsing bluecoat logs. While I try the same search from the cluster master the parsing is done properly but from any of the search heads....

There has not done any change in the cluster but suddenly the parsing stopped working.

Any ideas on where to focus my troubleshooting?

Labels (1)
0 Karma

harsmarvania57
Ultra Champion

Hi,

When you say parsing on search heads, do you mean search time extraction is not working on Search Heads for Bluecoat logs ?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...