Getting Data In

Splunk "sendall" command only uploading partial data...

Path Finder


Due to some data streaming issue from our source, I am trying to recover our large data and sent the decoded results to Splunk.
However, when I send the data to Splunk some percent of events fails to be uploaded. For example, when I try to upload 217177 events I only get 215438 events successfully uploaded. This is not a data size issue. When I try to upload something smaller like 100k events only 99994 get through.

Here is the commands I am using to upload the events:
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((HOST, PORT))
myRef= s.sendall(splunkString + '\n')

Can anyone suggest a fix?

Many thanks!

Tags (2)
0 Karma

Path Finder


0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!