Getting Data In

Splunk "sendall" command only uploading partial data...

pkurt
Path Finder

Hello,

Due to some data streaming issue from our source, I am trying to recover our large data and sent the decoded results to Splunk.
However, when I send the data to Splunk some percent of events fails to be uploaded. For example, when I try to upload 217177 events I only get 215438 events successfully uploaded. This is not a data size issue. When I try to upload something smaller like 100k events only 99994 get through.

Here is the commands I am using to upload the events:
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((HOST, PORT))
......
myRef= s.sendall(splunkString + '\n')

Can anyone suggest a fix?

Many thanks!
Pelin

Tags (2)
0 Karma

pkurt
Path Finder

resolved....

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...