Getting Data In

Logs Not Being Indexed

alexspunkshell
Contributor

Hi All,

I have 10 index.  But in1 index logs were not being indexed frequently.

Restarting HF fixing this issue for few days. And again same issue persist. How to find root cause of this issue and fix this permanently.

@isoutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana   @to4kawa 

 

Labels (3)
Tags (2)
0 Karma

alexspunkshell
Contributor

@thambisetty  Input is through monitor from Forwarder.

In splunkd.log i can see only recent logs. I want to find rca in yesterday's log. Can u help here?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@alexspunkshell 

what kind of input are you referring above. is that monitor or network or script?

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...