Hello,
I have had an issue where specifically the firewall logs were cutoff for about 5 hours and then reconnected and started logging again in Splunk.
The syslog server responsible is actually running and sending data, but how can I troubleshoot why the logs were not sent during that specific time period ?
I am new to troubleshooting indexers etc. any help is appreciaited.
Regards,
PS by "syslog server responsible" I meant the firewall management software responsible was logging all the events at the time of cutoff, might have used a wrong term there