Getting Data In

Indexing issue- Why is data going on and off?

ssuluguri
Path Finder

Hi Team,

 

We are ingesting data from syslot to splunk using Cyberark App . Data is going ON and OFF even though data available on /var/log/Cyberark .

ssuluguri_0-1689102150618.png

 

Can you suggest what can be the issue .

Labels (1)
0 Karma

mansisona
New Member

I am facing the same issue while using a scripted input. Did you find any ways to identify the root cause and fix it ? We are receiving data from a scripted input. we also tried putting that data in a csv file which has all the data. but still we are observing issues with data missing 

0 Karma

meetmshah
Builder

Hello @ssuluguri, Can you please confirm below - 

  1. How the _time is being extracted? If it's based on events - can you validate if the timestamp extraction is performed correctly?
  2. Can you check queues on the indexers?
  3. Can you run the search on real-time in Splunk along with running tcpdump on the host and validate if both are matching?
0 Karma

ssuluguri
Path Finder

You can also refer below screenshot.

ssuluguri_0-1689189394557.png

 

0 Karma

ssuluguri
Path Finder

Thanks for the reply Meet.

1.Data is indexing on cloud 

2.Data automatically populating for sometimes and going OFF.

Backend raw data .

ssuluguri_0-1689188937411.png

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...