Getting Data In

Why did we experience a Log drop from Gsuite?

akasmika
Loves-to-Learn

Hi Splunkers,

We are streaming google app logs to splunk in distributed environment. We have G suite for Splunk app on SH and Input add-on on Heavy forwarder. I am seeing log drop on a particular day for about 2 hrs and then the logging has turned normal. Unable to identify the reason for the same.

akasmika_0-1648579964460.png

Also the g suite application health dashboard shows the below error,

akasmika_1-1648580100762.png

@alacercogitatus , could you please help me identify the cause for logs drop and how to fix these errors?

Labels (2)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

I'd need app name and version. "G Suite" is not supported. "Google Workspace" is. You can also shoot me an email at the listed https://splunkbase.splunk.com/app/5498/ and we can triage there. But I need the app and version first to correlate that line number. Thanks!

0 Karma

akasmika
Loves-to-Learn

App and Version on SH: https://splunkbase.splunk.com/app/3791/ (1.4.2)

Input add-on on HF and version: https://splunkbase.splunk.com/app/3793/ (1.4.2)

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Those aren't supported due to Python2 and "old sdk" from google. Please upgrade and see if you still get that drop. Thanks!

0 Karma

akasmika
Loves-to-Learn

@alacercogitatus , the app or add-on version we have is the latest one I can see on splunk base(1.4.2) What surprises me is the logs have not stop completely but only for sometime. How can python or old sdk be the cause while it is working partially.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...