Getting Data In

How can I index data in real time?

chintan_shah
Path Finder

I have created an alert which checks if logs are not present in last 20 mins per source. I have around 32 source files from single forwarder. Many of my files are not getting indexed in real time and I am receiving this alert frequently.

Can anyone tell me any parameters which needs to be changed so that I can index the data in real time?
is there any mechanism to check what is the inflow rate of the data?

System Info:
I also see my CPU is around 80% idle and working Windows OS. I have 4 Core machine 32gb ram
Splunk Enterprise 6.4.3

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

@chintan_shah - First, please determine whether the files are not being indexed in a timely manner, or not being forwarded in a timely manner.

Second, check through the debug steps at "I can't find my data"

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Hi @chintan_shah,

Are you getting any error in Splunk Universal Forwarder's splunkd.log ?

Thanks,
Harshil

0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...