Getting Data In

Splunk

Priya70
Explorer

n/a

Labels (2)
0 Karma

Priya70
Explorer

N.A

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This should works correctly.
When you are saying “restart UF”, are you meaning splunk UF process or whole windows node?
Any reason why you are using separate ntpd instead of domain time? Have you checked how big time difference is after hibernation? You are aware that there are limits how big time difference ntpd can manage by itself without additional synchronization?
0 Karma

Priya70
Explorer

N.A

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
How quickly that sw update node’s time to correct after hibernation? Basically after that UF’s cron schedule should work as expected. If not then I propose that you should create a support case to Splunk.
0 Karma

Priya70
Explorer

N.A

0 Karma

isoutamo
SplunkTrust
SplunkTrust
So UF recognize the change of time when it writes this message into log, but its scheduler didn’t understand it correctly to run next round at correct time. Definitely time to create splunk support case.
0 Karma

Priya70
Explorer

N/A

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you paste your inputs.conf here between editor's script block </> ?

When you are saying "cheduled runs are sometimes missed, or scripts execute at unexpected times." is the only fix for this to restart splunkd service on UF?

Are those UFs in domain or just individual nodes which manages time sync with ntpd instead of Windows domain service?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...