Getting Data In

How to detect Splunk log ingestion failure?

sonam
Explorer

I'm working with Splunk setup to copy and index disk logs from remote servers using scheduled rsync transfer.

The rsync transfer job has a bandwidth limit specified to avoid overloading the remote servers and the Splunk server.

During a recent incident, this rsync bandwidth limit was reached because logs grew too quickly (about 5 GB/hour for about a day). During this time, logs were not transferred for indexing.

This is as designed, but Splunk reports nothing for that timeframe, nor gives an indication that data is missing.

Our Splunk admin says the rsync transfer failures cannot be reported. Is there a way to use Splunk to detect when logs were not indexed as expected?

0 Karma

lguinn2
Legend

You could turn on the Splunk Deployment Monitor app (it comes with Splunk).

It has some dashboards that show which forwarders are forwarding LESS than usual. You can also set alerts from within the Deployment Monitor.

This is why I don't like using rsync unless it is absolutely necessary. You end up having to manually deal with the corner cases when rsync doesn't work. Using a Splunk forwarder is a lot less hassle.

0 Karma

sonam
Explorer

Thanks - that sounds sensible.

0 Karma

RicoSuave
Builder

I would just set up an alert that emails you once a certain number of events falls below your given threshold.

sonam
Explorer

Yes, that would work but may cause a few false positives; for example, when a server was down for maintenance.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...