Getting Data In

Splunk

Priya70
Explorer

n/a

Labels (2)
0 Karma

Priya70
Explorer

N.A

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This should works correctly.
When you are saying “restart UF”, are you meaning splunk UF process or whole windows node?
Any reason why you are using separate ntpd instead of domain time? Have you checked how big time difference is after hibernation? You are aware that there are limits how big time difference ntpd can manage by itself without additional synchronization?
0 Karma

Priya70
Explorer

N.A

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
How quickly that sw update node’s time to correct after hibernation? Basically after that UF’s cron schedule should work as expected. If not then I propose that you should create a support case to Splunk.
0 Karma

Priya70
Explorer

N.A

0 Karma

isoutamo
SplunkTrust
SplunkTrust
So UF recognize the change of time when it writes this message into log, but its scheduler didn’t understand it correctly to run next round at correct time. Definitely time to create splunk support case.
0 Karma

Priya70
Explorer

N/A

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you paste your inputs.conf here between editor's script block </> ?

When you are saying "cheduled runs are sometimes missed, or scripts execute at unexpected times." is the only fix for this to restart splunkd service on UF?

Are those UFs in domain or just individual nodes which manages time sync with ntpd instead of Windows domain service?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...