Getting Data In

Logs sending being cutoff

STU3
Engager

Hello,

I have had an issue where specifically the firewall logs were cutoff for about 5 hours and then reconnected and started logging again in Splunk.

The syslog server responsible is actually running and sending data, but how can I troubleshoot why the logs were not sent during that specific time period ?

I am new to troubleshooting indexers etc. any help is appreciaited.

Regards,

0 Karma

STU3
Engager

PS by "syslog server responsible" I meant the firewall management software responsible was logging all the events at the time of cutoff, might have used a wrong term there

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...